logo

SquareX Researchers Uncover OAuth Vulnerability in Chrome Extensions Days Before Major Breach

ID: 6803c9cf-5474-58b7-b312-95a6c492bbe7

STIX ID: report--6803c9cf-5474-58b7-b312-95a6c492bbe7

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2024-12-30

Date Updated: 2026-04-21

Author: Balaji N

...
...

SquareX reports on a broad campaign that uses OAuth consent phishing to compromise Chrome extension developer accounts and push malicious updates; a malicious update to the Cyberhaven Chrome extension was published on December 25, 2024 (available ~30+ hours) and could hijack authenticated sessions and exfiltrate credentials across corporate web applications. The report describes the phishing-to-OAuth-consent attack chain, notes the scale (extension had ~400,000 users), highlights MV3-related exploitation techniques, and recommends stricter extension monitoring, OAuth blocking, and SquareX BDR mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.