Customers using Kaspersky Antivirus to protect their devices may have had their online activity tracked without their permission, experts have warned.
Millions of Kaspersky users may have had their browsing monitored for several years, a new report has said, with individual machines identified and every page visited recorded.
All of the company's antivirus products are thought to be affected by the issue, Kasperky admitted, meaning millions of users could be at risk.
- Kaspersky: We're ready to go to the next level
- Kaspersky Free Antivirus review
- Kaspersky shifts customer data out of Russia
"That's a remarkably bad idea," Eikenberg wrote in c't magazine (opens in new tab). "Other scripts running in the context of the website domain can access the entire HTML source any time, which means they can read the Kaspersky ID. In other words, any website can read the user's Kaspersky ID and use it for tracking."
Investigating the software on a test laptop, Eikenberg found that even when other visitors came to his site using other computers, the software would read their Kasperksy ID and address them personally, even if they deleted cookies.
Eikenberg notified Kaspersky of the problem, with the company later confirming that the issue existed on all versions of its antivirus software.
Kaspersky has now patched all affected software, and published a security advisory (opens in new tab) alerting users to the flaw.
If you think you've been affected, Kaspersky says the best thing to do is ensure your software is updated to the latest version, with patches available on your device or via the company's website.
"Kaspersky has changed the process of checking web pages for malicious activity by removing the usage of unique identifiers for the GET requests," the company said in a statement. This change was made after Ronald Eikenberg reported to us that using unique identifiers for the GET requests can potentially lead to the disclosure of a user’s personal information."
"After our internal research, we have concluded that such scenarios of user’s privacy compromise are theoretically possible but are unlikely to be carried out in practice, due to their complexity and low profitability for cybercriminals. Nevertheless, we are constantly working on improving our technologies and products, resulting in a change in this process."
"We’d like to thank Ronald Eikenberg for reporting this to us."
- The best antivirus software of 2019
Via Tom's Guide (opens in new tab)