Update Your Flash Player Right Now (Yes, Again)

Update Your Flash Player Right Now (Yes, Again)

Tech News adobe browsers flash security

So Adobe pushed out an emergency Flash Player patch today, and if you haven't already clicked through eleven different "update available" dialogs to get it, go do that now. I'll wait.

The short version: there are two zero-day vulnerabilities in Flash that are already being used in actual attacks, not just theoretical lab stuff. One of them was showing up in the wild through Word documents with a malicious Flash file embedded inside — somebody emails you a .doc, you open it because it looks like it's from someone you trust, and the Flash object inside quietly does its thing before you've even scrolled past the first paragraph. FireEye is the outfit that flagged it, and Adobe turned around a fix fast enough that I actually have some grudging respect for their security team this time, even if I have basically none left for Flash as a product.

I've been running this blog since the tail end of 2011 and I feel like I write some version of this post every few months. New Flash exploit, emergency patch, update your plugin, repeat. At this point it's less "breaking news" and more like a seasonal chore, the tech equivalent of changing your furnace filter. Except the furnace filter doesn't also get used to install spyware on your machine if you forget about it for a month.

Here's my actual opinion, which I realize is not a hot take in 2013 but I'll say it anyway: Flash needs to die faster than it's dying. Steve Jobs wrote that whole "Thoughts on Flash" letter back in 2010 and got dragged for being petty about it, and yeah, some of his reasoning was self-serving (of course Apple wanted native apps in the App Store instead of Flash content nobody could monetize the same way). But the security argument has aged pretty well. Every couple months there's a new critical vulnerability, and it's always the kind where the fix is "update immediately" because it's already being exploited, not the kind where some researcher responsibly disclosed it six months early and everyone patched calmly. HTML5 video and canvas are good enough now for most of what people actually use Flash for on the open web. The only places I still genuinely need it are a couple of client dashboards from work that nobody's bothered to rebuild, and some old Newgrounds-era Flash games I still load up when I'm procrastinating.

If you're on Windows or Mac, Adobe's advisory covers both the standalone Flash Player and the version bundled into Chrome (which updates itself automatically, one small mercy). If you're using Flash inside Internet Explorer 10 on Windows 8, that one's also covered but you'll want to grab it through Windows Update rather than Adobe's site directly, because Microsoft ships its own packaged version. Firefox and Safari users need to go through Adobe's downloads page like it's still 2009.

A small aside since I'm already complaining: can we talk about how many of these update dialogs also try to sneak McAfee Security Scan onto your machine via a pre-checked box? I almost installed it by accident today because I was moving fast and just kept hitting "next." That's such a small, dumb, annoying thing but it happens on basically every Adobe installer and it's been happening for years. Uncheck the box. Always uncheck the box.

Anyway. If you manage any Windows machines for family members, or you're the unofficial IT department for your office the way I apparently still am for my mom's laptop, this is a good week to go around and make sure Flash actually updated instead of just showing you the reminder icon in the corner forever. The exploit here isn't some nation-state cyberweapon aimed at defense contractors, at least not exclusively — it's the kind of thing that ends up in exploit kits within a week or two and gets sprayed at anyone running an old version. Takes about ninety seconds to update. Do it before you do anything else today, then go back to whatever you were actually trying to do on the internet.