Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - What Are The Security Implications Of Chrome 55 And The End Of Flash?
Articles

What Are The Security Implications Of Chrome 55 And The End Of Flash?

ISBuzz TeamBy ISBuzz TeamJanuary 11, 2017Updated:July 15, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The latest browser statistics published in W3Schools show that Google Chrome’s popularity continues its upward flow relative to other browsers (Firefox, Safari, IE); it has now surpassed 70 percent of all usage over the past six months. With the ongoing aggressive campaign of Chrome in Google Search, we can surely expect Google Chrome to hit the magic 80 percent threshold of browser usage in the next few months.

When matched with Chrome’s projected growth curve, the release of Chrome 55 doesn’t bode well for the future of Flash. According to the Google blog, the Flash experience would meet its demise in December with Chrome 55, but subsequent tests on both Windows 10 and macOS showed that the browser did not restrict what’s rendered by Flash. The jury is, indeed, still out.

Beyond the future of Flash however lies a more burning question: What does this development mean for Flash vulnerabilities across the internet? In a non-Flash, or at least reduced Flash environment, where do the DevOps and security teams need to turn their attention? This article will seek to address these questions.

figure-1
                     Figure 1 – The rise of Chrome since 2009
figure-2
           Figure 2 – Monthly growth numbers

The HTML5 Takeover

In the recent update to Chrome 55, Google clearly showed its desire to transition the Flash experience to HTML5, by default. The main reasons are performance improvements, reduced power consumption for mobile users, and faster page load times. All of these contribute to the Google brand promise that technology always serves the user with the best possible experience.

However, there was one additional and potentially more significant reason for Google’s decision: improved security. This is because Flash is a very vulnerable engine that has been taken advantage of the most by common exploit kits.

Exploit kits, Flash and their interdependencies

Exploit kits are web toolkits that use payloads to uncover vulnerabilities in software, and they have been particularly effective when using Flash as the “way in” to remotely infect devices with malware. When we look at the most famous exploit kits from 2016 such as Angler, RIG, Neutrino or Magnitude, they are all heavily reliant on Flash vulnerabilities.

figure-3
Figure 3 – Magnitude EK and its exploits of CVE-2016-4117, affecting Flash versions 21.0.0.226 and earlier. – Credit to Kaffine (Malware don’t need coffee)

With the high usage number and the convergence to Chrome, we can expect the end of Flash very soon – but what will happen to the exploit kits market?

Security Implications of a Flash-less Web

There’s always a target

The client-side web exploitation market will be the most clearly affected. Security researchers will probably shift their reverse-engineering efforts to other engines, such as JS, SVG or any other objects supported in HTML5, putting those objects at a higher risk.

Are Chrome Extensions the Next Way In?

Regardless of whether we are indeed at the ‘end of Flash’, Chrome’s meteoric rise will see a simultaneous rise of attacks involving Chrome extensions, such as last year’s major AVG extension vulnerability. As Flash becomes harder to exploit, vulnerabilities will enter through paths of lesser resistance.

Backward Compatibility

Although Flash is being all but completely trimmed out from web browsers (Firefox, Edge & Safari have already abandoned Flash), there are still many websites that require Flash support, and these will keep the exception mechanism open. It is not far-fetched to say that Flash applications are likely to persist, perhaps in perpetuity, and the exception mechanisms represent a security weak point that cannot be ignored.

Moreover, not all tech consumers will know that Flash has been all but eliminated due to security concerns. Malicious actors will be able to successfully attack using social engineering techniques. Perhaps they will be able to convince users to enable Flash to view specific content, then slide in the open door. This method is quite similar to the exploitation methods behind the use of macro files to break into MS Office.

Adaptive Approach

Although it’s not yet known what the next browser-based attack will look like, we can hazard some guesses for the above reasons. Ultimately, it is only a matter of time until the next attack vector introduces itself. The advance of Chrome and the phasing out of Flash doesn’t mean the end of known vulnerabilities, but should rather serve as a reminder that security teams stay focused on maintaining the right intelligence, infrastructure and personnel that can adapt on a dime and take swift action. Fortunately, for organizations that must run lean in terms of their network architecture and IT staff, emerging security-enabled SD-WAN technology puts application control features into the cloud.

[su_box title=”About Elad Menahem” style=”noise” box_color=”#336588″][short_info id=’100249′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read

New Federal Alert Warns U.S. Businesses of Medusa Ransomware Surge

March 13, 20254 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}