SquareX Researchers Uncover OAuth Vulnerability in Chrome Extensions Days Before Major Breach
ID: 6803c9cf-5474-58b7-b312-95a6c492bbe7
STIX ID: report--6803c9cf-5474-58b7-b312-95a6c492bbe7
Feed Name: cybersecurityNews.com
SquareX reports on a broad campaign that uses OAuth consent phishing to compromise Chrome extension developer accounts and push malicious updates; a malicious update to the Cyberhaven Chrome extension was published on December 25, 2024 (available ~30+ hours) and could hijack authenticated sessions and exfiltrate credentials across corporate web applications. The report describes the phishing-to-OAuth-consent attack chain, notes the scale (extension had ~400,000 users), highlights MV3-related exploitation techniques, and recommends stricter extension monitoring, OAuth blocking, and SquareX BDR mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
