AVG's 'Secure Search' Toolbar May Create Security Risk

Security problems don't look good on any company's record, but they're particularly unflattering for companies that specialize in digital security. Amsterdam-based antivirus-software maker AVG Technologies suffered a blow yesterday (July 7) when the U.S. Department of Homeland Security warned of serious flaws in AVG's Secure Search browser toolbar that affect Microsoft Internet Explorer.

The AVG Secure Search toolbar is meant to protect users from malicious websites and sites that collect their browsing information. However, the U.S. Computer Emergency Response Team (US-CERT), a joint project of DHS and Carnegie Mellon University in Pittsburgh, found that attackers could remotely seize control of a computer using the Internet Explorer version of the toolbar.

MORE: Best Free PC Antivirus Software

AVG has already released an update to the Secure Search toolbar, which can be found on the company's website. If you'd rather remove AVG Secure Search from Internet Explorer entirely, here's how to reset your Internet Explorer settings.  

The AVG Secure Search flaw exists in the way the toolbar interacts with Microsoft's ActiveX software framework, heavily used in Internet Explorer. AVG Secure Search contains an ActiveX control called ScriptHelperApi that websites shouldn't be able to access.

Websites can in fact invoke ScriptHelperApi, according to US-CERT, resulting in a remote-code-execution flaw that could let an attacker install and run malware, or gather personal data, on an affected computer. There's no evidence this flaw was exploited in the wild, but attackers could have created a specially crafted malicious Web page, tricked AVG Secure Search users into visiting it and then taken over their computers.

If you use any AVG products, you probably have the AVG Secure Search toolbar installed. It comes bundled with most AVG software, such as the company's free PC antivirus product (our review of which can be found here), as well as other free software downloads such as media players.

The toolbar is not always clearly marked during installation, nor is it easy to remove, leading some people to dub AVG Secure Search "foistware," unwanted software foisted upon users of a separate product, or a "potentially unwanted program" (PUP).

Aside from being annoying and cluttering, such undesired software creates yet another entry point that attackers could use to gain access to your computer. Each piece of software is a possible avenue for attackers, which is why you want to install only the most trustworthy programs.

Most people don't know they're downloading AVG Secure Search to begin with, much less that it contained such a serious flaw. AVG has now patched this flaw, as US-CERT researcher Will Dormann informed AVG of his findings several weeks ago. AVG's update went live June 1, more than a month before Dormann authored US-CERT's report.

Email jscharr@tomsguide.com or follow her @JillScharr and Google+.  Follow us @TomsGuide, on Facebook and on Google+.

TOPICS

Jill Scharr is a creative writer and narrative designer in the videogame industry. She's currently Project Lead Writer at the games studio Harebrained Schemes, and has also worked at Bungie. Prior to that she worked as a Staff Writer for Tom's Guide, covering video games, online security, 3D printing and tech innovation among many subjects. 

Latest in Online Security
A magnifying glass on top of the Steam logo in a web browser
Valve just pulled a malicious game demo spreading info-stealing malware from Steam
A man filing his taxes electronically on a laptop
AI-powered tax scams are here - how to stay safe from deepfakes, phishing and more this tax season
MacBook Pro 2023
New Mac attack is tricking users into thinking their computer is locked — how to stay safe
Hacker using a stolen social security card
Your Social Security number is a literal gold mine for scammers and identity thieves — here’s how to keep it safe
An open lock depicting a data breach
Half a million teachers hit in major data breach with SSNs, financial data and more exposed — what to do now
Green skull on smartphone screen.
Malicious Android apps with 60 million installs bombarding phones with ads and phishing attacks — how to stay safe
Latest in News
Galaxy S25 Ultra Now brief
Samsung’s Personal Data Engine is a big addition to the Galaxy S25 — here’s why
Apple Watch Series 10
Future Apple Watch models could get a surprising new feature — what we know
NYTimes Connections
NYT Connections today hints and answers — Monday, March 24 (#652)
NYT Strands on a cellphone
NYT Strands today — hints, spangram and answers for game #386 (Monday, March 24 2025)
iPhone 16 Pro vs iPhone 16 Pro Max in hand showing displays
Forget iPhone 17 — iPhone 18 could get this huge upgrade
The new Husqvarna iQ series robot lawn mower.
Husqvarna’s new robot mowers offer GPS for less
  • rayden54
    So Insecure Search Toolbar?
    Reply
  • plasmastorm
    Malware removal programs such as ADW Cleaner have been removing it for months as a security risk
    Reply
  • dextermat
    It's sad to see an antivirus program be classified as PUP or even malware....
    AVG get bundle with program and installs without knowing if not careful.
    Also slows down computers to a crawl. Been black listed for a while on my computers.
    Reply
  • redgarl
    It was a good anti-virus 3 years ago, now it is just a marketing tool...
    Reply
  • hoofhearted
    Agreed. Love how it bombard you with popups after your free version expires. Even malwarelike in that it puts the popups back after you gut em out.
    Reply
  • Murissokah
    Toolbar = malware.
    Reply