Google Chrome bug allegedly allows attackers to eavesdrop and record your voice

Advertisement
By NDTV Correspondent | Updated: 13 February 2014 13:01 IST
An alarming bug has been discovered in Google Chrome that could allow attackers to surreptitiously record your voice and everything around you. Israeli web developer and entrepreneur Tal Ater discovered the problem last September while working on a JavaScript speech recognition project. After seeing no concrete action from Google to fix the problem, he has now posted proof to his personal website.

According to Ater's description, the flaw is possible because of the way different parts of Chrome were designed. While there is a clear indication to users on the tab bar when a website has activated your PC's mic or camera, there is no way to display such a notification on popup windows. Thus a website which has been granted permission to use your microphone (such as Google's own homepage, when voice search is enabled) can quietly spawn popups in the background which will inherit the permission but not display any indication that they are recording you.

Websites could thus be compromised, and a user might never know that a pop-under page has opened behind their open browser window. A user would have no way to know such a window is open, and it could be disguised as just another ad.

Advertisement

Compounding the problem, Chrome remembers permissions granted to pages that use the HTTPS protocol, trusting them to be secure. Thus, users aren't even asked to confirm whether they would like to allow a page to activate the mic.

Ater says he contacted Google on September 13 2013 and was informed less than a week later that the root causes problem had been identified. Five days after that, a patch had been developed. Ater says he was nominated for a reward under a Google scheme that pays up to $30,000 (approximately Rs. 18,72,300) to ethical developers who discover and report such bugs.

Advertisement

However the patch was never released to the public or applied to future releases of Chrome. Ater claims that Google does not believe that there is anything wrong with the way Chrome behaves. In a statement to UK news site The Register, Google said, "The feature is in compliance with the current W3C specification, and we continue to work on improvements."

We attempted to recreate the problem and confirmed that Chrome tabs with voice input enabled do display a pulsing red dot in the tab bar, but do not cut off the microphone when the user switches to another tab or program. We were prompted for permission the first time we used a voice input feature on any website, but not on subsequent uses. Furthermore, there is no indication outside of Chrome that anything is being recorded. This means that background windows are indeed capable of recording a user's voice and surroundings without his or her knowledge.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. OPPO K14 5G Overview: Segment's Smoothest and Longest-Performing Smartphone Under ₹25,000
  2. Vivo X300 FE Arrives in India With a 50-Megapixel Zeiss Camera at This Price
  3. OnePlus 16 Could Get 200-Megapixel Camera, These Other Upgrades
  4. Vivo X300 FE Review: A Strong Contender With a Catch
  5. iPhone 18 Pro CAD Renders Confirm Smaller Dynamic Island
  6. Pragmata Review: The Bright Side of the Moon
  7. Realme 16T 5G Could Launch in India Soon as Marketing Image Leaks Online
  8. Vivo X300 Ultra First Impressions
  9. Vivo X300 Ultra Debuts in India With 200-Megapixel Zeiss Cameras: See Price
  10. CMF Watch 3 Pro With Up to 13 Days Battery Life Launched in India
  1. OnePlus 16 Specifications Tipped Again; to Get 200-Megapixel Camera, Snapdragon 8 Elite Gen 6 Pro SoC
  2. iPhone 18 Pro CAD Renders Reveal Smaller Dynamic Island, Identical Rear Camera Design
  3. Astronomers Discover Trans-Neptunian Object With Atmosphere in Outer Solar System
  4. Samsung's One UI 8.5 Update Finally Rolls Out to Galaxy S25 Series, S24 Series, S25 FE, Z Fold 7 and Z Flip 7
  5. Samsung Galaxy A27 5G Shows Up on Geekbench Again With Slightly Improved Performance Scores
  6. Adobe Unveils New Productivity Agent for Acrobat, Adds New Features to PDF Spaces
  7. Google's May 2026 Update for Pixel Devices Rolls Out With Fixes for Slow Wireless Charging, Screen Freezing Issues
  8. Colombia Seeks to Mine Bitcoin Using Surplus Renewable Energy From Country's Coastline
  9. CloudZ RAT Malware Could Exploit Microsoft Phone Link App to Access Messages and OTPs, Researchers Warn
  10. Vaazha II: Biopic of a Billion Bros OTT Release Date: When and Where to Watch This Malayalam Drama Film Online
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.