Microsoft Investigating Mouse Tracking Flaw in Internet Explorer

Latest Videos FromTom's Hardware
Kevin Parrish
Contributor

Kevin Parrish has over a decade of experience as a writer, editor, and product tester. His work focused on computer hardware, networking equipment, smartphones, tablets, gaming consoles, and other internet-connected devices. His work has appeared in Tom's Hardware, Tom's Guide, Maximum PC, Digital Trends, Android Authority, How-To Geek, Lifewire, and others.

  • chicofehr
    I'm sure Microsoft is using this themselves which is why they don't seem bothered to fix it. Google probably wants this flaw to remain as well.
    Reply
  • spartanmk2
    When has internet explorer ever not had a vulnerability...
    Reply
  • A Bad Day
    Internet Explorer versions 6, 7, 8, 9 and 10.

    I wonder if MS is going to patch one of those two browsers IF they get around to the exploit, or at least IE7?...

    Anyways, I already installed IE10, but I suppose I'll have wait for a while considering the fact that how easy it is to upload malware-loaded advertisements.
    Reply
  • A Bad Day
    Spartanmk2When has internet explorer ever not had a vulnerability...
    When was there a software that was invulnerable except for ones completely inaccessible by humans (or not created by a human, because a jerk can set a critical embedded software to delete itself at 2012 Dec 21st before loading it to the devices).
    Reply
  • joytech22
    Tracking cursor movement is about as useful as being blindfolded and trying to hit a pinata from 1000km away.
    Reply
  • beayn
    What purpose would tracking cursor movement have? It's not like it's stealing passwords.
    Reply
  • alextheblue
    joytech22Tracking cursor movement is about as useful as being blindfolded and trying to hit a pinata from 1000km away.That's kind of what I was thinking. If it doesn't send information other than cursor location and ctrl, shift, alt key status, it's not much of a vulnerability.
    Reply
  • As far as tracking the relative positions of a 10 key key pad that some banking websites use to defeat key loggers, I guess some banks can randomize the layout of the 10 key pad to defeat that vulnerability!
    Reply
  • arson94
    Well.... If I were to write messages to these "hackers" using my mouse cursor, like I moved my cursor around my desktop to write "Lick balls, bitch" would they receive my message? If not, then I guess I wouldn't call it much of a hack. They would probably think that my computer was infected with real malware that sporadically moved my mouse cursor around uncontrollably.
    Reply
  • SteelCity1981
    how about more ie version updates instead of coming out with a new version every two years. IE should be at least v15 right now.
    Reply