Google Fixes Chrome 'Evil Cursor' Bug Abused by Tech Support Scam Sites

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12+hMV1_azgphf056vj0O8UwndP0=ap42EiaV94Zzu=Z6A@mail.gmail.com>
'Google has patched a Chrome bug that was being abused in the wild by
tech support scammers to create artificial mouse cursors and lock
users inside browser pages by preventing them from closing and leaving
browser tabs. From a report:

The trick was first spotted in September 2018 by Malwarebytes analyst
Jerome Segura. Called an "evil cursor," it relied on using a custom
image to replace the operating system's standard mouse cursor graphic.
A criminal group that Malwarebytes called Partnerstroka operated by
switching the standard OS 32-by-32 pixels mouse cursor with one of 128
or 256 pixels in size. A normal cursor would still appear on screen,
but in the corner of a bigger transparent bounding box. [...] The
"evil cursor" fix is currently live for Google Canary users, and is
scheduled to land in the Chrome 75 stable branch, to be released later
this spring.'

-- source: https://tech.slashdot.org/story/19/03/25/210220

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.