Hackers hijack a wide range of companies' Chrome extensions, experts say

Discussion in 'other security issues & news' started by ronjor, Dec 27, 2024.

  1. ronjor

    ronjor Global Moderator

    Joined:
    Jul 21, 2003
    Posts:
    177,020
    Location:
    Texas
    By Raphael Satter and A.J. Vicens December 27, 2024
     
  2. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    27,166
    Location:
    UK
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Seriousy this is crazy stuff, I wonder why nobody is outraged about this. How on earth can extensions steal cookies and authenticated sessions? When will browser developers tackle this problem? Or perhaps it will be solved by the upcoming MV3?
     
  4. FanJ

    FanJ Updates Team

    Joined:
    Feb 9, 2002
    Posts:
    4,921
    See also Extension Total:
    Cyberhaven Incident
    https://www.extensiontotal.com/cyberhaven-incident-live

    They have a long list!
    It was last updated on 11:08 UTC January 1st, 2025

    Read there more.
     
  5. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    18,178
    Location:
    The Netherlands
    Yes I saw it. And the weirdest thing is, that it's still not possible to disable auto-updating of extensions in Chromium based browsers. This would have actually stopped this attack. I do believe this is possible in Firefox.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.