In an advisory published today, a Google researcher points out that security company Comodo, with its suite of tools for its customers to stay safe online, is exposing them to potential attacks.
Well-known Google researcher Tavis Ormandy reports that the Comodo Internet Security suite installs a browser called Chromodo and sets it as the system's default browser upon installation.
Ormandy reports that when installing Comodo Internet Security:
“All shortcuts are replaced with Chromodo links and all settings, cookies, etc. are automatically imported from Chrome. The application also invades DNS settings, with suspicious practices.”
What's particularly worrying is that Chromodo disables Chrome's same-origin policy, which allows a script to access data from another script only if both are on the same site.
Without this setting in place, users are vulnerable to attackers who can attempt to intercept their traffic via malicious websites.
Following the Lenovo Superfish adware fiasco last February, Comodo was found to have added man-in-the-middle code to its applicationto use self-signed certificates, making it very easy for hackers to spy on the company's customers.
If you are one of those who uses the Comodo Internet Security suite on your computer, you should stop using the application's browser.
