A group of hackers, called eGobbler, is exploiting a security found in Google Chrome that allows it to deliver malicious ads to iOS users.
Researchers working on the case (from the company Confiant) discovered that this vulnerability since April 6 and estimate that over 500 million iOS users have been infected with malicious ads.
Users are tricked and taken to pages that claim to be winning something. These pages are run by hackers.
Google is already trying to find a solution to fix the error.
The bug affects the way the Chrome browser for iOS handles pop-ups. Chrome uses ad sandboxing featuresthat prevent pop-ups from appearing unless the user activates them. However, with this vulnerability, hackers can bypass this protection mechanism.
Standard sandboxing settings, which normally block certain redirects, failed to protect users.
Researchers identified 8 different “hacking campaigns,” associated with the eGobbler group, targeting iOS users in the US. The attacks began on April 6 and each lasted 1-2 days.
Experts believe that the eGobbler hackers are planning other campaigns, targeting other platforms.
