Hello everyone, I’m new here and I’ve got a fairly serious question/problem.
I’ve used Bromite for a long time, and now with the threat of CVE-2023-4863, I can’t help but constantly fear getting screwed over by a malicious image. I’ve tried looking myself but cannot find an answer if bromite is vulnerable to this threat, mostly because the main developer of the browser hasn’t been active for a very long time.
I’d love to switch to another browser but to transfer all my data would require root access, which could damage my pixel 6. So I’m kinda stuck in a jam.
Can anyone please help me?
Unfortunately browsers need at least a monthly security update. Bromite doesn’t have a commit since January, so it’s dead. And the last release is from December. Even if for some reason it didn’t have that specific webp vulnerability, it has 11 months of other security issues. You must stop using it immediately right now
For a browser there’s no data to transfer except the few bookmarks and the opened tabs (you aren’t using a dead browser with no sync as your only password manager, right?). Install a new browser, then share the bookmarks and tabs one by one.
I don’t understand how root can break your Pixel (it doesn’t void warranty) but anyway unlocking the bootloader for rooting requires a full wipe and all you can get is a config database that could only be used with bromite (or forks, if they didn’t change too much)
For your next browser choose one that has hundreds of devs as staying behind updates is a massive task and a small team (or a single person) like the one behind bromite can easily burnout and disappear overnight.
Thank you for your reply, I don’t look forward to transferring things over one by one, but it is a better idea than me just Freaking out. As for worrying about breaking my phone, I do not consider myself very smart, so reading that there is a chance that rooting your phone can brick it scares me.
As for a password manager, I’m not completely stupid, I use an offline app which is updated fairly regularly and is quite secure.
sigh Guess I’d better get to working on this sooner rather than later. Thank you again for your reply.
If you like Bromite there is a fork of it called Cromite https://github.com/uazo/cromite
Or you could try Mulch https://divestos.org/pages/our_apps#mulch
Both are Chromium browsers
Thank you for the reply, I was aware of Cromite, though not of Mulch. Considering how Bromite turned out, I’m looking at Vivaldi at this point for my new browser.
Remember to keep Android System Webview updated as well.
MORE BROMITE FORKS!
Does the webp vulnerability (CVE-2023-4863) affect the Bromite browser?
Yes
I’d love to switch to another browser but to transfer all my data would require root access, which could damage my pixel 6. So I’m kinda stuck in a jam.
Transferring your data to Firefox does not require root access
Ah, I see. Thank you for the swift answer, though I’m afraid I don’t know what you mean by just transferring to Firefox. Bromite is an android browser and does not have a sync function, which prevents me from easily getting to the app data and moving it to a new android browser. If I’m mistaken can you give me a link?
What data in particular are you after pulling from Bromide?
I’ve never used it so not aware of its interface but most browsers allow you to grab your usernames / passwords (tip: it’s a bad idea to store them in a browsers data and a password manager the better route) even if it means doing each one individually if it doesn’t allow mass exporting of data.
But as the above commenters have said using an out of date browser is something to put some time aside to fix. Good luck!