Loading video...
Video Failed to Load
Google Chrome on macOS installs a background app called GoogleUpdater that starts automatically after a restart. With this macOS bug, its executable can be silently replaced with any code. No password. No warning. The user is completely unaware. Hers's a demo (clipboard spy)
125,070 views • 1 month ago •via X (Twitter)
18 Comments

This is actually a good reminder to uninstall Google Chrome if you already have it 😎 Link to the video on YouTube:

Would it be possible to build a scanner to detect modified apps ?

Yes

All the Google Chrome supporters using a malware infested browser then crying out for help will be comedy gold.

Every day that goes by shows how prescient the bottom-up security model of Hydra/Plan 9 was… and the world's failure to adopt it is an exponentially growing detrimental momentum.

Gemini app does the same thing. Every time I disable it and reopen the app it turns itself on I hate it so much

is it only chrome or all chromium based browsers?

@googlechrome look at this shit

So now we're using macos bugs to hate on chrome?

Ppl so retarded they still use chrome

It's TCC bypass right?

No, the clipboard API is open for all apps on macOS. It is not protected by TCC

Oh sorry I commented on the wrong post. I am asking about this:

Also no, because macOS prompts the user for permission when the replacement executable tries to access TCC protected folders. But the prompt looks the same as if the original executable requested it

Ah! thanks for the clarification.

If you run malicious or untrusted code, then, do you expect it to be unable to access data from your apps? Before saying it's a critical security issue, maybe check how other operating systems protect you from malicious code you run?

Çocukluk alışkanlığınız olan Chrome'dan vazgeçin.

Nice
