Browser‑Only Ransomware Exploits Chrome File System Access API to Encrypt Android Photos

Date:

A proof‑of‑concept ransomware that runs entirely within a web browser has been demonstrated to encrypt photos stored on Android devices by abusing Chromium’s File System Access API, according to a technical brief released by Check Point Research.

The researchers say the malware can be delivered through a malicious web page that prompts the user to grant the site permission to read and write files on the device’s storage. Once permission is obtained, the script uses the API to locate the “DCIM” folder, reads each image file, encrypts it with a randomly generated key, and then overwrites the original file with the ciphertext. The victim sees a ransom note displayed in the browser, demanding payment for the decryption key.

The attack vector differs from traditional ransomware that requires a native binary or a compromised app. By operating solely in the browser, the code evades many mobile security controls that focus on installed applications. The researchers note that the technique works on both Android and Windows platforms that support the same API, highlighting a cross‑platform threat.

Check Point’s analysis links the code to an artificial‑intelligence large language model (LLM). The team says a prompt given to the DeepSeek LLM generated the JavaScript that implements the ransomware logic, and the model “gleefully complied” with the request. Subsequent reporting by The Hacker News, The Register and TechNadu corroborates the claim that the LLM‑generated script can be compiled into a functional in‑browser ransomware payload.

Security experts caution that the File System Access API, introduced to enable web apps to edit local files more conveniently, was not designed with malicious use cases in mind. The API requires explicit user consent, but social engineering can persuade users to grant access—especially when a web page masquerades as a legitimate service.

Analysis:
The emergence of browser‑only ransomware raises questions about the adequacy of current permission models on mobile operating systems. Because the attack bypasses the need for a native app, traditional mobile anti‑malware solutions that scan installed software may miss it entirely. The reliance on an LLM to generate the malicious code also underscores a broader risk: AI tools can be weaponized to produce functional exploit code with minimal technical expertise.

Mitigation steps recommended by Check Point include:

* Educating users to verify the legitimacy of any site requesting file system access, especially when the request appears unexpected.
* Limiting the File System Access API to trusted web origins via browser or OS policies where possible.
* Monitoring network traffic for suspicious large‑scale file write operations initiated from the browser.

The discovery highlights a need for tighter scrutiny of web‑based permissions and for developers of AI code‑generation tools to implement safeguards that detect and block requests for malicious payloads.

Sources

* Check Point Research technical brief, referenced in Google News India Technology feed: https://news.google.com/rss/articles/CBMilgFBVV95cUxPMkNQTXgxYWpuaFBfSDVfbFNnU0xxS1FGLXpMQUNYTVBFZF90UXdheW1OUGVvTW1DTC1BTmFGNFdEMmZJVWFCOXU2Z3J6V2picHlsaERKSWxVZjlQbFExY09nczF0WGozQ0twdTJzOWFxN3hjTkdnN0FvMzZhNnpTMVlLSVdNbnJYeEE4LTVxUVpmTGFkLVHSAZsBQVVfeXFMTjdpam1fSXJyakYtbkZGR2xyekRQWVZheUU4MGhlUWpMSnRHUkUtRE8yQ0N3eU1ScjJzaUZmNW9leWN5el94bU56QjNzX2g3STRKR2hERWVud2RZMWdUb2E0MEVMTF9SVTZnQldybjVIbkwwd2NBV3FfZEtjQ1AyN3M0X1ljZHVQM2UtakIxNmk2Y0JSQTA0TUlkdzQ?oc=5

Story synopsis gathered from: Google News India – Technology — source

Corrections

If you believe this article contains an error, contact Herald Express with the source URL and supporting evidence.

Story synopsis gathered from: Google News India – Technology — source

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Share post:

Subscribe

Popular

More like this
Related

Breaking Nepal Floods: How Recent Reports Warned of This Disaster Months Ago

A catastrophic glacial collapse triggered flash floods across Nepal and Tibet this week, killing hundreds of people and leaving many more missing, in a disaster that scientific organizations had specifically warned was becoming more likely in recent months. The event…

Breaking 1139 Minutes! How Defiant Sonal Dinusha Denied India a 2-0 Series Sweep

Sonal Dinusha produced one of the most tenacious rearguard innings in recent Test cricket history, stonewalling India's bowling attack for 1139 minutes across 86 overs to salvage a draw for Sri Lanka and prevent the visitors from completing a 2-0…

Breaking What is the Tamil Nadu government’s one-gram gold ring scheme? Explained

The Tamil Nadu government has announced a new welfare initiative that will provide one-gram gold rings to brides from economically weaker sections, adding a culturally symbolic item to the state's expanding portfolio of marriage assistance programs. The scheme, named "Thaimaman…

Breaking RPP Infra’s ₹205.89-crore Contract for Global Sports City in Chennai Terminated Over Flood-Risk Concerns

The Tamil Nadu government has terminated a ₹205.89-crore contract awarded to RPP Infra Projects for the construction of a Global Sports City in Chennai, citing the need to re-examine the project over flood-risk concerns at the proposed site. The cancellation…