Security firm Imperva has revealed a Chrome browser security flaw dubbed CVE-2022-3656, which has affected more than 2.5 billion users and allowed the theft of sensitive files, including encrypted wallets and cloud service provider certificates. An attacker could create a fake website offering a new encrypted wallet service, which could trick users into creating a new wallet by asking them to download their "recovery" keys, which are actually a zip file containing Contains symbolic links to sensitive files or folders on the user's computer. When the user unzips and uploads the "recovery" key back to the website, the symbolic link will be processed and the attacker will gain access to the sensitive file.