logo

Updated: Google warns of unauthorized TLS certificates trusted by almost all OSes | Ars Technica

ID: 8c1e575f-2458-5699-a84c-ec57aba3e3da

STIX ID: report--8c1e575f-2458-5699-a84c-ec57aba3e3da

Feed Name: Security Ledger

Threat Score
70/100

Date Published: 2015-03-24

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

Google disclosed that unauthorized digital certificates for multiple Google domains were issued by an intermediate CA held by MCS Holdings and rooted at CNNIC. Because CNNIC is included in major root stores, those certificates would be trusted by most browsers and OSes and could be used to impersonate sites or perform man-in-the-middle interception; Google blocked the intermediate in Chrome and reported no confirmed abuse at the time.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.