A vulnerability in the CSS3 attribute, named “mix-blend-mode,” allowed an attacker to remove the anonymity of a Facebook using Google Chrome or Mozilla Firefox by causing them to visit a specially crafted website.
The flaw, which has now been fixed, was discovered last year by research duo Dario Weißer and Ruslan Habalov and separately by another researcher named Max May.
The demo the researchers created allowed them to collect data such as profile picture, username and information related to “likes” from unsuspecting visitors, the researchers said in a blog post. All of this can be done in the background when a user visits a malicious website.
Data leakage can occur on websites that use iFrames that connect to Facebook in the form of social plugins and login buttons.
POC takes about 20 seconds to reveal a username, about 5 minutes for a blurred version of the profile picture, and about 500 milliseconds to check the like status. However, the target user will need to be logged into their Facebook account for the method to work.
Both Google and Mozilla were privately notified by the researchers, but the fact became public last year, as independent researcher Max May had already posted it on the Chromium mailing list in March 2017.
The vulnerability was patched for Google Chrome last December (version 63). For Firefox, the patch became available two weeks ago (version 60). This is because the researchers encountered an issue that delayed its disclosure to Mozilla until November 2017.
The vulnerability did not affect IE and Edge as the web browsers do not support the required functionality. Safari was also not affected.
While the flaw has been fixed, researchers warn that the advanced graphics capabilities added to HTML and CSS could pave the way for more attacks like these.
