Skip to main content

Google’s Project Zero chastised Trend Micro over security vulnerability

google said to be planning new messaging app that uses ai headquarters sign
Image used with permission by copyright holder
When you pay for security software, you probably hope it’s protecting you — not creating a massive security breach in and of itself. But if you ran Trend Micro’s password manager, enabled by default for all Trend Micro users, any site on the web could have executed any app on your computer just by including a bit of code.

A patch issued today mostly solves the problem. But as Ars Technica reports, that only happened because Google Project Zero team member Tavis Ormandy publicly berated the company.

Recommended Videos

“I don’t even know what to say — how could you enable this thing by default on all your customer machines without getting an audit from a competent security consultant?” wrote Ormandy in a long email exchange the company has since made public.

Please enable Javascript to view this content

Ormandy claimed it took him “about 30 seconds” to find the vulnerability, and demonstrated it by quickly building a Web page that could remotely launch the Windows calculator if opened on a computer with the password manager installed and running — regardless if users were using it.

That’s true even if you don’t use the password manager, but it gets worse if you do: A related vulnerability made it possible to read all of a users’ saved usernames and passwords in plain text.

A recent update patches the exploit by only allowing Trend Micro sites to send such commands. If you use Trend Micro, make sure everything is up to date, or you might be extremely exposed to all sorts of problems.

But even if you do update, there still could be problems. As of today, Ormandy is saying this “is not sufficient to prevent attacks,” because something like DNS spoofing could trick your computer into thinking a command is coming from Trend Micro. Ormandy added that “a better solution would be to digital sign requests with a certificate.”

Google Project Zero is a team of security researchers inside Google that find zero-day exploits, problems that would otherwise be exploited by hackers. The team gives software companies 30 days to fix the problem, at which point they make it public. The idea is to make the Internet a safer place by getting these exploits fixed before hackers can use them, though this has prompted controversy: Some companies feel this isn’t enough time. It is more time than a hacker would grant, though.

Justin Pot
Former Digital Trends Contributor
Justin's always had a passion for trying out new software, asking questions, and explaining things – tech journalism is the…
Upgrade to this Samsung OLED gaming monitor while it’s $300 off
The Samsung Odyssey OLED G6 gaming monitor on a white background.

Upgrading your rig with gaming PC deals won't matter if you're still using an old screen. If budget permits, we highly recommend investing in a top-of-the-line display, such as the 27-inch Samsung Odyssey OLED G6. Originally $900, this gaming monitor is down to $650 from B&H Photo Video, for savings of $250. You can also clip a $50 coupon to drop it down to $600. You're going to want to hurry in completing this transaction though, as we're not sure how long stocks will last. Before more gamers discover and take advantage of this offer, push through with your purchase right now.

Why you should buy the 27-inch Samsung Odyssey OLED G6 gaming monitor
Samsung's Odyssey line is a fixture in our roundup of the best gaming monitors, which currently includes the Samsung Odyssey OLED G8 and Samsung Odyssey OLED G9. The Samsung Odyssey OLED G6, however, is also an excellent option for gamers. It all begins with Samsung's OLED technology, bringing it from OLED TVs to this gaming monitor for stunning visuals while you play the best PC games. The 27-inch screen also offers a 360 Hz refresh rate and 0.03 ms response time, eliminating lag and motion blur for a completely immersive experience, and 2560 x 1440 resolution for lifelike details and colors.

Read more
Windows 11 to finally address this webcam deficiency
Lenovo Yoga Slim 7x front view showing webcam.

The latest Windows 11 Insider Preview Build (26120.2702) was released a couple of days ago and it adds a new camera feature that probably should have been added ages ago. Once the build rolls out to all Windows 11 PCs, you'll be able to let multiple apps use your camera at the same time.

Microsoft says the reason it developed this feature is to "enable video streaming to both a sign language interpreter and the end audience at the same time" but users will surely find a range of uses for it.

Read more
I tried out Google’s latest AI tool that generates images in a fun, new way
Google's Whisk AI tool being used with images.

Google’s latest AI tool helps you automate image generation even further. The tool is called Whisk, and it's based on Google’s latest Imagen 3 image generation model. Rather than relying solely on text prompts, Whisk helps you create your desired images using other images as the base prompt.

Whisk is currently in an experimental phase, but once set up it's fairly easy to navigate. Google detailed in a blog post introducing Whisk that it is intended for “rapid visual exploration, not pixel-perfect edits.”

Read more