Google Chrome bug allegedly allows attackers to eavesdrop and record your voice

Advertisement
By NDTV Correspondent | Updated: 13 February 2014 13:01 IST
An alarming bug has been discovered in Google Chrome that could allow attackers to surreptitiously record your voice and everything around you. Israeli web developer and entrepreneur Tal Ater discovered the problem last September while working on a JavaScript speech recognition project. After seeing no concrete action from Google to fix the problem, he has now posted proof to his personal website.

According to Ater's description, the flaw is possible because of the way different parts of Chrome were designed. While there is a clear indication to users on the tab bar when a website has activated your PC's mic or camera, there is no way to display such a notification on popup windows. Thus a website which has been granted permission to use your microphone (such as Google's own homepage, when voice search is enabled) can quietly spawn popups in the background which will inherit the permission but not display any indication that they are recording you.

Websites could thus be compromised, and a user might never know that a pop-under page has opened behind their open browser window. A user would have no way to know such a window is open, and it could be disguised as just another ad.

Compounding the problem, Chrome remembers permissions granted to pages that use the HTTPS protocol, trusting them to be secure. Thus, users aren't even asked to confirm whether they would like to allow a page to activate the mic.

Advertisement

Ater says he contacted Google on September 13 2013 and was informed less than a week later that the root causes problem had been identified. Five days after that, a patch had been developed. Ater says he was nominated for a reward under a Google scheme that pays up to $30,000 (approximately Rs. 18,72,300) to ethical developers who discover and report such bugs.

Advertisement

However the patch was never released to the public or applied to future releases of Chrome. Ater claims that Google does not believe that there is anything wrong with the way Chrome behaves. In a statement to UK news site The Register, Google said, "The feature is in compliance with the current W3C specification, and we continue to work on improvements."

We attempted to recreate the problem and confirmed that Chrome tabs with voice input enabled do display a pulsing red dot in the tab bar, but do not cut off the microphone when the user switches to another tab or program. We were prompted for permission the first time we used a voice input feature on any website, but not on subsequent uses. Furthermore, there is no indication outside of Chrome that anything is being recorded. This means that background windows are indeed capable of recording a user's voice and surroundings without his or her knowledge.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme GT 8, Realme GT 8 Pro With Ricoh GR Optics Launched: See Price
  2. OnePlus 15 Battery Capacity, Charging Speed Teased Days Ahead of Launch
  3. iQOO 15 Launched With Snapdragon 8 Elite Gen 5, 50-Megapixel Cameras
  4. Jio Adds JioCloud Storage to Business Broadband Plans in India: See Price
  5. These Are the 5 Biggest OxygenOS 16 Features You Should Know About
  6. OnePlus 15 India Launch Teased; Key Features Revealed Ahead of Launch
  7. BSNL Samman Plan For Senior Citizens Announced at This Price
  8. Vivo X300 Pro, Realme GT 8 Pro, Poco Pad M1 Certified, Could Launch Soon
  9. Sony WH-1000XM6 Review: The Best Just Got Better
  10. Diwali Blackout: How the AWS Outage Crippled Major Apps Across the World
  1. CERT-In Asks Mozilla Firefox Users to Install Browser Updates to Remain Safe From Security Vulnerabilities
  2. WhatsApp Will Soon Crack Down on Spam by Limiting Messages in New Chats: Report
  3. Baai Tujhyapayi OTT Release Date Revealed: Know Everything About Streaming, Plot, Cast, and More
  4. OnePlus 15 Launch in India Teased via Microsite; Company Reveals Key Features Ahead of China Debut
  5. BSNL Samman Plan Announced For New Senior Citizen Users: Price, Benefits
  6. Daksha: The Deadly Conspiracy Is Streaming Now: Know All About This Mohan Babu, Lakshmi Manchu Starrer
  7. Vivo Led Market as Smartphone Shipments in India Rose 3 Percent YoY in Q3 2025: Omdia
  8. DeepSeek-OCR Open-Source AI Model Changes How AI Models Read and Process Plain Text
  9. Vivo X300 Pro, Realme GT 8 Pro and Poco Pad M1 Listed on TDRA Site, Could Launch Soon
  10. Poco F8 Ultra Listing on NBTC Certification Website Hints at Imminent Launch
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.