Millions of Enterprises at Risk: SquareX Shows How Malicious Extensions Bypass Google’s MV3 Restrictions
ID: 1dff5d30-eead-5215-ad49-8ba89b6a6565
STIX ID: report--1dff5d30-eead-5215-ad49-8ba89b6a6565
Feed Name: cybersecurityNews.com
SquareX presented research at DEF CON showing that malicious Chrome extensions can still bypass Manifest V3 protections to steal sensitive data (site cookies, browsing history, bookmarks, live video streams), act on behalf of users (e.g., add collaborators to private repos), hook login flows to capture credentials, and push malicious downloads; the report warns enterprises that current EDR/SSE/SWG tools lack visibility into extensions and describes SquareX’s Browser Detection and Response product as a mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
