0 Record(s)
We found results matching "0" in 0 ms

Avast AntiTrack certificate errors make it possible for others to spy on your online activities

Apr. 2, 2020

A vulnerability impacting Avast and AVG AntiTrack privacy software opened up user PCs to Man-in-The-Middle attacks, browser session hijack, and data theft. 


Disclosed by David Eade on March 9, the security researcher said the security flaw, tracked as CVE-2020-8987, is a certification validation issue that affects Avast AntiTrack before and AVG AntiTrack before 


Attackers do not need local access to trigger the vulnerability, and no special software configuration needs to be in place. 


Avast's AntiTrack software is designed to block advertising trackers and to prevent "invasive" monitoring of your online habits. However, a set of three security failures undermined these goals. 


The first issue has been caused by a failure to check the validity of certificates presented to end servers. In these cases, self-signed, malicious certificates may be missed, permitting attackers to launch MiTM attacks. 


The second security problem outlined by the researcher is how Avast AntiTrack downgrades browser security protocols to TLS 1.0. Even if a web server supports TLS 1.2, the software will ignore these settings and make connections to TLS 1.0 websites -- and when it comes to browsers that have been configured to only reach websites supporting the higher standard, Avast's software should not ignore such direction.


The third problem is a failure for AntiTrack to honor browser cipher suites or Forward Secrecy, a means to ensure session keys are not compromised.


Eade disclosed the security problems to Avast on August 7, 2019. After several months, the vulnerabilities were dealt with internally, but it was not until 9 March 2020 that a public patch had been deployed for both Avast and AVG AntiTrack, both of which share a similar core code.


Avast thanked the researcher for his findings, saying that the vulnerability has now been patched in Avast AntiTrack version and AVG AntiTrack version The update has now been pushed out to users.


Bzfuture shares software news and advice on big data software and platforms. Don't forget to keep an eye on our weekly newsletter for more information.Get all the software products you need from the bzfuture online retail store. Connect with our customer service online.

CloseWelcome to Bzfuture Sign In.

Not signed up yet?   Sign Up Now

Log in with a third party account:

Open the bzfuture APP

Scan The code to login

CloseWelcome to Bzfuture Sign Up.

  • Email Address*

    Please enter a valid Email.

  • Mobile Phone*

    Please enter a valid mobile phone.

  • Verification Code*

    Get Verification Code

    The code will be invalid in 5 minutes

  • Password*

    5 to 16 letters, numbers, and special characters.

  • Confirm Password*

  • First Name* Last Name*

  • I have read and agreed to the  
    Subscribe to Bzfuture Offers ,Contests&Newsletter.

Already have an Bzfuture account?   Sign In Now

Log in with a third party account


Prompt T698563:

The programe has been successfully submitted to the system


Prompt T698563:

The programe has been successfully submitted to the system


Prompt T698563:

The programe has been This is a warning ?

CloseSuccessful Registration

CloseSecurity verification