Chrome Security Update Addresses 23-Year-Old History Leak Bug
  • 293 views
  • 2 min read

A recent security update for the Chrome browser has addressed a vulnerability related to how browsing history is handled, a flaw that has persisted for over two decades. This "history leak bug" potentially allowed websites to discern a user's browsing history without explicit permission, raising significant privacy concerns. The update, rolling out with Chrome version 136, introduces a new mechanism called ":visited link partitioning" to mitigate this risk.

The core of the issue stemmed from the way Chrome, and indeed most web browsers, traditionally handled visited links. Web browsers use CSS to style the links so users can see which links they've visited. This is done via the “:visited” pseudo-class in CSS, which allows developers to change the color of visited links, usually to purple. The flaw resided in the fact that this information about visited links was not properly isolated between different websites. This meant that if a user visited "Site B" from "Site A," a malicious website ("Site Evil") could detect this visit simply by checking the styling of a link pointing to "Site B." This technique, known as "browser history sniffing," has been a known problem for many years, with various mitigations implemented over time, none of which completely solved the underlying issue.

Google characterizes this as a core design flaw where browser cookies indicating whether or not you click on a link were “unpartitioned.” This meant that if you clicked a link, it would show as visited on every website displaying that link, even if it was completely unrelated.

Chrome's new approach, :visited link partitioning, fundamentally alters how visited links are tracked and managed. Instead of maintaining a global list of visited links accessible to any website, Chrome will now store each visited link with contextual details such as the link URL, the top-level site, and the frame origin. This ensures that a link is only identified as "visited" within the specific context where it was actually clicked. In the previous example, "Site Evil" would no longer be able to determine if the user had visited "Site B" from "Site A," as the visited status would be specific to the "Site A" context.

The implications of this update are significant. By isolating browsing history in this way, Chrome 136 effectively eliminates a long-standing privacy risk. Malicious websites can no longer exploit the ":visited" CSS pseudo-class to infer a user's browsing habits, preventing potential exposure of sensitive information related to health, finances, or political views.

It is worth noting that this particular vulnerability has been a known issue for a considerable time. Bug reports related to this have existed in Chromium's issue tracker for years. The fact that Google has now addressed this issue head-on demonstrates a renewed commitment to user privacy and security.

While previous mitigations slowed down history detection attacks, they did not eliminate them. Chrome 136's new system renders these attacks obsolete. According to Google, this update is a defining moment for browser security. The company is committed to building a safer web for everyone.

Users are encouraged to update to Chrome 136 to take advantage of this enhanced privacy protection. The update is currently available through the Chrome Beta channel and is expected to roll out to the stable channel soon. Keeping your browser up to date is essential for maintaining a secure browsing experience and protecting your privacy online.


Writer - Anjali Kapoor
Anjali possesses a keen ability to translate technical jargon into engaging and accessible prose. She is known for her insightful analysis, clear explanations, and dedication to accuracy. Anjali is adept at researching and staying ahead of the latest trends in the ever-evolving tech landscape, making her a reliable source for readers seeking to understand the impact of technology on our world.
Advertisement

Latest Post


Infosys is strategically leveraging its "poly-AI" or hybrid AI architecture to deliver significant manpower savings, potentially up to 35%, for its clients across various industries. This approach involves seamlessly integrating various AI solutions,...
  • 424 views
  • 3 min

Indian startups have displayed significant growth in funding, securing $338 million, marking a substantial 65% year-over-year increase. This surge reflects renewed investor confidence in the Indian startup ecosystem and its potential for sustainable ...
  • 213 views
  • 3 min

Cohere, a Canadian AI start-up, has reached a valuation of $6. 8 billion after securing $500 million in a recent funding round. This investment will help Cohere accelerate its agentic AI offerings. The funding round was led by Radical Ventures and Ino...
  • 320 views
  • 2 min

The Indian Institute of Technology Hyderabad (IIT-H) has made significant strides in autonomous vehicle technology, developing a driverless vehicle system through its Technology Innovation Hub on Autonomous Navigation (TiHAN). This initiative marks a...
  • 375 views
  • 2 min

Advertisement

About   •   Terms   •   Privacy
© 2025 TechScoop360