Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Editor Blogs > Web

May 24th, 2012, 14:30 GMT · By

BLOG

Yahoo Axis Chrome Extension Removed Due to Vulnerability

SHARE:

Adjust text size:


The Chrome version of Yahoo Axis had a vulnerability Enlarge picture - The Chrome version of Yahoo Axis had a vulnerability
Yahoo Axis may be an interesting, though not revolutionary app, but the launch casts a bit of a shadow on Yahoo's prowess as a tech company.

The Chrome version of the app was found to have a rather serious security flaw so it's been pulled down until further notice.

It's not a huge issue, but it's not a minor one either. The Yahoo Axis Chrome extension leaked its internal certificate key, which it uses to verify its authenticity with the Google Chrome Web Store.

Basically, it's the thing that tells Chrome that the extension really is Yahoo Axis and that it did originate from Yahoo.

But with the certificate made public, any developer can forge it and create an extension that will look like it was created by Yahoo. That extension could then be able to do all sorts of nasty things to a computer.

TELL US WHAT YOU THINK:

981 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Yahoo Complains That Facebook Bought Patents Just to Attack It

The New Gmail Design Is Now Being Forced on Users, Here's What You Can Do

Script of the Day: Yahoo! WebPlayer

Facebook to Debut IPv6 Test Site Ahead of World IPv6 Launch Day in June

Chrome OS 20 Dev Update Brings Support for Bluetooth Mice and Keyboards

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM