We received the following notification from Google:
------------------------------------------------------------------------------------------------
[Security Alert]: Polyfill.io Issue for Google Maps Platform users
6/28/24, 7:03 PM
Hello Google Maps Platform Customer,
We're writing to let you know that a security issue may be affecting websites using specific third-party libraries (including polyfill.io).
What happened
We have become aware of a security issue that may be affecting websites using specific third-party libraries (including polyfill.io). This issue can sometimes redirect visitors away from the intended website without website owner knowledge or permission, or potentially cause other malicious behavior. Many of the Maps JavaScript API samples in the Developer Documentation previously included a polyfill.io script declaration. We have removed this from those samples. If you have used the Maps JavaScript API samples that contain this declaration, we recommend removing the declaration.
What to do
Please see below to learn how to take action, if needed:
Investigate your website: Check your website's code to see if you're loading any compromised libraries (including polyfill.io).
Remove or replace the code: If you find compromised libraries, consider:
Hosting a clean, secure version of the code yourself
Switching to an alternative library or provider
Removing the library if you don’t need it
Re-deploy your code through your regular process.
-------------------------------------------------------------------------------------------
The only place we're currently using Google Maps is in the Toolset Maps plugin on one of our websites. We're needing to determine if the plugins uses polyfill.io, and if so, will you be issuing an update to address this vulnerability?
Thank you for your help,
Barney Royalty
Focus on the Family