Now Reading
Google has a secret browser hidden contained in the settings

Google has a secret browser hidden contained in the settings

2023-06-26 06:13:03

I just lately found a secret browser situated contained in the “Handle my account” popup that Android has in numerous apps (fairly necessary apps, corresponding to Settings, and all Google suite apps). The browser even bypasses parental management!

My site open inside Settings app in my Android phone

How one can get there?

Getting there…. takes some work:
1. Go into Settings→Google (or any app that allows you to select your account) and click on on “Handle my account”.
2. Then go to the “Safety” tab. In there, scroll down till you discover “Password Supervisor”. Click on on it.
3. Click on on the ‘Settings’ icon within the top-right.
4. Scroll down till “Arrange on-device encryption” seems. Click on on it, then click on on “Be taught extra about on-device encryption”.
5. Now you might be within the browser. However you wish to go to Google.com! So click on on the hamburger menu, then click on “Privateness Coverage”.
6. Faucet the 9 dots on the prime, wait 5 seconds (it takes a while to load) and click on “Search” (For those who don’t discover the search icon, you may as well scroll down till ‘Google’ and click on on that)
7. Logout out of your Google account.
8. You bought the key browser ! You possibly can go wherever. It’s also possible to play YouTube movies (with advertisements, sadly), and all of that is within the settings app (or no matter app you select) !

LiveOverflow in Settings app

Browser overview:

Execs: It’s a reasonably non-public browser : it has no historical past and it auto logs out of all Google accounts that have been logged-in, on the finish of the session.

Cons: the obvious one is the again key, which suggests each time you press the again key, as a substitute of going again one tackle within the historical past, it goes again into the password handle settings, however I suppose it might be thought of a bonus – as an emergency key for privateness.

The identical goes for no tackle bar. (However have a look at the glass half full: it nonetheless doesn’t advertise itself on the installation page of other browsers).

However there are one other issues that forestall this browser from being a safe browser: The damaging capabilities.

The damaging capabilities:

As I used to be utilizing this browser, I found a wierd factor. A bizarre JavaScript object named mm. To see this, go to eruda, (simply because it’s the most effective cellular JavaScript console I do know) and kind mm

Screenshot of eruda expend the `mm` object
Screenshot of eruda expend the mm object

As you see, there are three capabilities:

Let’s begin with closeView() operate, as a result of it’s the one clear operate: it simply closes your browser, as would occur in case you press the again key. Not a normal JavaScript operate, however nothing to fret about. (you’ll be able to strive it proper there by typing into eruda ‘mm.closeView()‘)

See Also

Then you may have two strategies which I don’t know what they do, however they sound scary. As it is a secret-browser of the ‘on-device encryption’ characteristic, I can guess, they’re each used to set your native encryption keys. So it appears to be like like a malicious web site can put their keys there, and attempt to make you pay for them!

I believe that is the time to inform you that I already reported this to Google, they usually say this isn’t a safety vulnerability (in all probability as a result of this secret browser will not be extremely popular), and that the parental management bypass is the “Meant Habits” ????

Google’s reply to my report

For those who take pleasure in utilizing it, please let me know within the feedback what you probably did with it.

Hope you take pleasure in your (new?) browser that you just didn’t know you had !

Source Link

What's Your Reaction?
Excited
0
Happy
0
In Love
0
Not Sure
0
Silly
0
View Comments (0)

Leave a Reply

Your email address will not be published.

2022 Blinking Robots.
WordPress by Doejo

Scroll To Top