logo

Millions of Enterprises at Risk: SquareX Shows How Malicious Extensions Bypass Google’s MV3 Restrictions

ID: 1dff5d30-eead-5215-ad49-8ba89b6a6565

STIX ID: report--1dff5d30-eead-5215-ad49-8ba89b6a6565

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2024-10-03

Date Updated: 2026-04-21

Author: Kaaviya Ragupathy

...
...

SquareX presented research at DEF CON showing that malicious Chrome extensions can still bypass Manifest V3 protections to steal sensitive data (site cookies, browsing history, bookmarks, live video streams), act on behalf of users (e.g., add collaborators to private repos), hook login flows to capture credentials, and push malicious downloads; the report warns enterprises that current EDR/SSE/SWG tools lack visibility into extensions and describes SquareX’s Browser Detection and Response product as a mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.