# Arc Browser RCE Vulnerability (CVE-2024-45489)

**URL:** https://discuss.privacyguides.net/t/arc-browser-rce-vulnerability-cve-2024-45489/21002
**Category:** Off Topic
**Created:** 2024-09-20T06:24:19Z
**Posts:** 30

## Post 1 by @jonah — 2024-09-20T06:24:19Z

> **[gaining access to anyones browser without them even visiting a website -...](https://kibty.town/blog/arc/)**
>
> gaining access to anyones browser without them even visiting a website

This is a wonderful read :slight_smile:

---

## Post 2 by @anon48875053 — 2024-09-20T06:25:45Z

This is what I expect from all of these new Chromium and Firefox forks.

Stick with proven options instead of chasing the new thing and new “cool” UI.

---

## Post 3 by @ph00lt0 — 2024-09-20T08:14:50Z

Honestly not surprising. As the saying goes, with a browser comes great responsibility. I don’t get why people jump on the boat of some smaller browser project without a dedicated security team.

---

## Post 4 by @anon48875053 — 2024-09-20T08:35:55Z

> [@ph00lt0](#):
>
> I don’t get why people jump on the boat of some smaller browser project without a dedicated security team.

Floorp and Zen are some recent examples, everyone just jumped on the hype train when those came out.

---

## Post 5 by @ignoramous — 2024-09-20T08:45:04Z

> [@ph00lt0](#):
>
> jump on the boat of some smaller browser project

Smaller? They seem on-par with most of the popular forks (Brave, Vivaldi etc)? [The Browser Company raises $50M at a $550M valuation | TechCrunch](https://techcrunch.com/2024/03/21/the-browser-company-raises-50-million-at-550-million-valuation/) / ([mirror](https://archive.md/cGhrc)).

> [@anon48875053](#):
>
> I expect from all of these new Chromium and Firefox forks

tbf, Arc is all-in on the cloud+AI thing (adding new security vulns) which some of the volunteer-maintained forks won’t have money for (thankfully, enough).

> [@jonah](#):
>
> This is a wonderful read :slight_smile:

Lessons… on recommending products / services because they “work well” but not actually pay attention to _what they do_ versus _whatever they say_ in their marketing including privacy policies (which has become another form of just that).

 ![Screenshot_2024-09-20-14-06-53-86_40deb401b9ffe8e1df2f1cc5ba480b12~2](//forum-uploads.privacyguidesusercontent.com/original/2X/3/32d66bda2e8b13bcc29e124b73694326f556c526.jpeg)

> [@NextDNS logging is opt-out, not opt-in as stated on PG's DNS Resolvers recommendations page](https://discuss.privacyguides.net/t/nextdns-logging-is-opt-out-not-opt-in-as-stated-on-pgs-dns-resolvers-recommendations-page/17206/53):
>
> This is something I raised in a subsequent email to them. I really like for example how Hashicorp does this: [Subprocessors](https://www.hashicorp.com/trust/privacy/subprocessors)
> 
> I think their policy is a bit bare bones and could do with improvements.
> 
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/ignoramous/48/11_2.png)[NextDNS logging is opt-out, not opt-in as stated on PG's DNS Resolvers recommendations page](https://discuss.privacyguides.net/t/nextdns-logging-is-opt-out-not-opt-in-as-stated-on-pgs-dns-resolvers-recommendations-page/17206/52)
> 
> > Then, what’s the point of NextDNS “storing” logs in Switzerland, if they’re going to be streamed through GCP servers worldwide (because if GCP is streaming logs stored in Switzerland through Indian servers, then Indian laws apply and GCP will comply with those laws)? PrivacyGuides makes it seem as if “storing” logs in the EU etc is a positive thing: `You can choose retention time and log storage location for any logs you choose to keep, or disable logs altogether.`
> 
> You could really argue that about any provider who uses any third party whether it be Azure, AWS or some other platform. If that is the new criteria we should just ban any service that doesn’t own their own servers and not single out GCP specifically.
> 
> That will basically mean we’re left with very few services/reliable services and will be throwing out a huge amount of products which actually do work well

---

## Post 6 by @ph00lt0 — 2024-09-20T08:58:59Z

> [@ignoramous](#):
>
> Smaller? They seem on-par with most of the popular forks (Brave, Vivaldi etc)? [The Browser Company raises $50M at a $550M valuation | TechCrunch](https://techcrunch.com/2024/03/21/the-browser-company-raises-50-million-at-550-million-valuation/) / ([mirror](https://archive.md/cGhrc)).

This is exactly what a hype is. Says pretty much nothing about the actual size of the company.

> [@ignoramous](#):
>
> Lessons… on recommending products / services because they “work well” but not actually pay attention to _what they do_ versus _whatever they say_ in their marketing including privacy policies (which has become another form of just that).

For the record, Arc was never recommended on PG.

---

## Post 7 by @ignoramous — 2024-09-20T10:18:50Z

> [@ph00lt0](#):
>
> For the record

I meant to point out that the position that something “works well” might not mean it _means well_, especially in terms of privacy, regardless of public claims (“gdpr”, “military-grade encryption”) or private assurances (“personally recieved guarantees via email”, “world-class experts”, etc).

> [@ph00lt0](#):
>
> Arc was never recommended on PG.

To be pedantic: The default position of defending existing recommendations as “accurate” (when questioned) & the irony of putting “incompetence” [[1]](#footnote-59382-1) in the title on coverage of a security & privacy breach of a service / product _not_ recommended by PG, is probably lost on some.

* * *

1. Title was changed ([mirror](https://archive.md/3LVuv)):

---

## Post 8 by @arandomduck — 2024-09-20T10:40:55Z

It’s the sickness of our age imo. Looks before the function. People are first interested in the looks of something, rather than its functions. This is also why people use closed-source terminals like Warp (see [issue](https://github.com/warpdotdev/Warp/issues/900)) that require a login and are sketchy as hell

---

## Post 9 by @asanyan — 2024-09-20T15:01:17Z

> [@ph00lt0](#):
>
> I don’t get why

Because these web browsers provide useful features not present in the parent browser. Floorp provides webapps for instance, which is a very useful feature that isn’t provided in upstream FF.

---

## Post 10 by @anon48875053 — 2024-09-20T16:08:09Z

> [@asanyan](#):
>
> Floorp provides webapps for instance, which is a very useful feature that isn’t provided in upstream FF.

Brave has PWA support, if you use PWAs, then you probably stay logged into your accounts, and Brave will be a more secure option.

---

## Post 11 by @asanyan — 2024-09-20T16:22:18Z

Yes, and there are many reasons on why Brave (and other chromium browsers) are unsuitable for some. Specially linux users.

---

## Post 12 by @sha123 — 2024-09-20T16:28:54Z

Which reasons?

---

## Post 13 by @asanyan — 2024-09-20T16:37:22Z

Manifest v2 deprecation, the fact that it is constantly broken if you use the native wayland version (it defaults to x11/xwayland), unfriendliness towards smaller screen resolutions

---

## Post 14 by @anon48875053 — 2024-09-20T16:45:34Z

> [@asanyan](#):
>
> Manifest v2 deprecation

That’s actually good, using MV2 extensions isn’t a good idea even if you trust the developer of the extension.

Even though I use Firefox on my Linux machine, I still use uBO Lite and not regular uBO.

---

## Post 15 by @asanyan — 2024-09-20T16:48:53Z

Why? Got an article on this?

---

## Post 16 by @anon48875053 — 2024-09-20T16:52:46Z

> **[4.1 Extensions](https://github.com/arkenfox/user.js/wiki/4.1-Extensions#-foreword)**
>
> Firefox privacy, security and anti-tracking: a comprehensive user.js template for configuration and hardening - arkenfox/user.js

We recommend keeping extensions to a minimum: they have [privileged access](https://blog.mozilla.org/attack-and-defense/2020/06/10/understanding-web-security-checks-in-firefox-part-1/) within your browser, require you to trust the developer, can make you [stand out](https://en.wikipedia.org/wiki/Device_fingerprint#Browser_fingerprint), and [weaken](https://groups.google.com/a/chromium.org/g/chromium-extensions/c/0ei-UCHNm34/m/lDaXwQhzBAAJ) site isolation. For those interested, [here](https://palant.info/categories/extension-security-basics/) is an ongoing series on the basics of browser extension security by Wladimir Palant.

This list covers privacy and security related extensions only. While we believe these are the very best of the best, this can be subjective depending on your needs. We are also not saying you have to use all these extensions.

* * *

MV3 extensions don’t need invasive permissions, one example is uBlock Origin Lite.

---

## Post 17 by @bluemonk — 2024-09-20T17:01:17Z

the bountry awarded was a whopping 2k, unbelievable for such a huge fuck up.

---

## Post 18 by @anon48875053 — 2024-09-20T17:02:50Z

Yeah, it’s pretty cringe, with bounties like that, it’s almost like they don’t even want people to penetration test their browser.

---

## Post 19 by @asanyan — 2024-09-20T17:06:23Z

While it’s true that privileged access should be kept at a minimum, many of the features of uBO cannot be replicated without privileged access.

> [@anon48875053](#):
>
> MV3 extensions don’t need invasive permissions, one example is uBlock Origin Lite.

I don’t think that’s true. Vimium is mv3 and it injects its javascript into web pages. That’s pretty privileged, I’d say.

---

## Post 20 by @anon48875053 — 2024-09-20T17:18:28Z

> [@asanyan](#):
>
> Vimium is mv3 and it injects its javascript into web pages.

Without giving it a permission to read and modify?

---

## Post 21 by @asanyan — 2024-09-20T17:24:59Z

No, but uBO also requires this permission.

---

## Post 22 by @anon48875053 — 2024-09-20T17:46:46Z

Yes, but not uBO Lite.

---

## Post 23 by @sha123 — 2024-09-21T06:41:25Z

> [@asanyan](#):
>
> Manifest v2 deprecation

I see

> [@asanyan](#):
>
> the fact that it is constantly broken if you use the native wayland version (it defaults to x11/xwayland)

That’s strange. I only experienced this one or two times on Arch+KDE.

---

## Post 24 by @eqrlzo8t — 2024-09-21T07:55:56Z

Any blockers, including uBOL, needs “invasive permissions” to block more complicated ads and trackers. Non-permission mode, aka, “Basic” mode is as it says: blocks basic things.

---

## Post 25 by @jonah — 2024-09-22T05:57:21Z

Arc is establishing a bug bounty program, is “bolstering” their security team, has hired a new security engineer, and has “verified that no one outside of the security researcher who discovered the bug has exploited it.”

> **[CVE-2024-45489 Incident Report – Arc](https://arc.net/blog/CVE-2024-45489-incident-response)**
>
> The Browser Company's response to CVE-2024-45489.

---

## Post 26 by @Broken — 2024-09-22T08:36:52Z

To be fair to Arc here, they at least seem to be attempting to do something about it, and seemed to fix the vuln pretty quick. Not that I would recommend this browser. But nontheless…

---

## Post 27 by @Valynor — 2024-09-22T12:57:54Z

> [@jonah](#):
>
> is “bolstering” their security team, has hired a new security engineer

Translation: they probably have 2 security engineers now. Max.

---

## Post 28 by @bluemonk — 2024-09-24T17:26:12Z

Some better news, her bounty is increased to 20k.

[https://nitter.lucabased.xyz/xyz3va/status/1838570171616686313#m](https://nitter.lucabased.xyz/xyz3va/status/1838570171616686313#m)

---

## Post 29 by @anon48875053 — 2024-09-24T17:31:56Z

That is a lot better.

---

## Post 30 by @whoami5 — 2024-09-24T17:54:02Z

> [@anon48875053](#):
>
> chasing the new thing and new “cool” UI.

It’s not just shiny UI. They provide a completely different feature set. Most useful for me are split view and “web panels” which quickly opens a mobile version of a site in the browser sidebar.

I am not an expert, but I don’t think these vulnerabilities apply to Floorp as it doesn’t add any cloud-based features. As long as it pushes firefox security patches in a timely manner then that covers vulnerabilities that would actually be exploited in the wild because they target a large install base.
