Security researchers from Nightwatch Cybersecurity have discovered a way to crash Chromium and Firefox browsers on mobile and desktop devices.
Their method relies on the use of the search suggestions feature that these browsers. The issue is not a software bug, but the design implementation that allows their attack to be carried out.
Most modern browsers have a search field or allow users to search via the URL address bar. Depending on the search engines supported within the browser, search suggestions may appear as the user types their query.
Nightwatch experts say that if a browser's search engine provider does not protect these search suggestions over an encrypted HTTPS channel, an attacker on the local network can intercept the queries and respond before the search provider does.
An attacker can inject large amounts of data into this response, which can lead to exhaustion of the browser or operating system's memory resources and ultimately cause it to crash.
The good news is that the researchers were not able to execute malicious code during these crashes, which would have caused more problems for browser.
During their testing, the researchers managed to crash the Android stock browser on Android 4.4, Chrome 51 on Android 6.01, and Firefox 47 on Ubuntu 16.04. Furthermore, they managed to crash the entire Ubuntu 16.04 OS when running Chrome 51.
For this crash to occur, as mentioned above, users must be using a browser's built-in search provider that doesn't use HTTPS. The list includes: Ebay for Firefox, AOL and Ask.com for Chrome, and Bing and Yahoo for Android's stock browser.
Internet Explorer, Edge, and Safari are not affected by this issue. Safari had to deal with its own search-related crash earlier this year, so its reputation isn't as "perfect" as you might think.
The Android, Chrome, and Firefox teams have refused to classify this bug as a security issue, since it actually isn't, which means a fix will come relatively soon.


