Skip to main content

Adobe promises fix for webcam-spying Flash bug

Aboukhadijeh Flash setting clickjack

Some technology flaws don’t go away—they just get a Band-Aid applied to them that eventually falls off. Adobe says it is working on a fix to an Adobe Flash vulnerability that enables attackers to trick Flash users into turning on their microphone and/or webcams, potentially enabling attackers to visually spy on them, overhear and record conversations, and obtain sensitive information. However, unlike most zero-day Flash exploits, this one doesn’t involve the Flash plug-in itself: instead, it uses interface obfuscation techniques to get users to unwittingly change their Flash player settings using a Shockwave Flash file hosted by Adobe itself.

Re-discovered by Stanford computer science student Feross Aboukhadijeh, the attack works by loading Adobe’s own Flash Player Settings Manager directly from Adobe, then using CSS, JavaScript, or other techniques to hide most of the interface and encourage users to click in locations that will enable Flash access to a user’s webcam or microphone. The attack relies on trickery and social engineering to get users to click in the right locations, rather than exploiting a bug in the plug-in or the Flash Player Settings Manager.

The technique is similar to a webcam settings attack that surfaced back in 2008; however, in that case attackers were loading the Flash Player Settings file into an iframe (essentially, a sub-region of a Web page that can be treated like a separate page), and using trickery to get users to click the settings options there. Adobe changed their settings file so it couldn’t be loaded in an iframe, but Aboukhadijeh realized that wasn’t actually necessary: just load the settings manager directly from Adobe, and you bypass Adobe’s anti-framing JavaScript code.

Aboukhadijeh reported the problem to Adobe, and apparently received no response. However, after disclosing the problem publicly Adobe has contacted Aboukhadijeh and said they are working on a fix that will not require an update to the Flash Player. As a result, Adobe likely won’t issue a security bulletin about the vulnerability. According to CNet, Adobe says a fix could be deployed by the end of the week.

Adobe has long been criticized for using a Shockwave Flash file on its own servers to enable user control of users’ settings on their local machines. Computer security experts and privacy advocates have also noted it makes the process of monitoring and clearing “Flash cookies”—also known as Local Shared Objects—considerably more complicated than it needs to be.

Topics
Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Lenovo designed a new modular webcam solution for its business monitors
Lenovo's new ThinkVision monitor works with modular webcam and speakerbar attachments.

While rivals HP and Dell have announced monitors at CES 2022 with built-in webcams and speakers designed for hybrid and remote work, Lenovo is taking a slightly different approach with its ThinkVision monitors.

Instead of building the video conferencing system permanently into the monitors, the new ThinkVision displays come with a modular solution that allows you to snap on either the webcam or the speaker, or both modules together, for a complete experience when collaborating with colleagues or connecting with friends over video.

Read more
Dell’s wireless, magnetic webcam fixes the eye contact problem in video calls
dell project pari magnetic webcam helps make eye contact concept 4

Dell has revealed Concept Pari, a completely wireless webcam that just happens to magnetize to surfaces. This isn't the first wireless webcam in existence, but Dell's implementation feels particularly magical, especially in regard to how it tries to establish eye contact.

Part of the appeal is its size. It weighs just one ounce and slots easily into its USB-C dock above Dell's monitor, where it can also charge wirelessly. Having seen the device in person, it really was remarkable just how light and small this webcam was.

Read more
Razer’s $79 Kiyo X webcam uses ring light software to replace its built-in light
Razer's new Kiyo X uses a virtual ring light to illuminate your face.

Razer is adding to its webcam lineup with a second Kyo model. Like the original $99 Kiyo, the new Kiyo X supports 1080p video calls, but comes in at a more affordable price of $79.

In fact, both webcams boast similar features -- 1080p streams at 30 frames per second (fps) or ultra-smooth 60 fps at 720p, a clip mount mechanism for easy attachments to monitors, and a compact, all-black design -- with the main difference being that the newer model scraps the dedicated ring light to help keep costs down.

Read more