Browser extension sales, updates pose hidden threat to enterprises
ID: 79c5e9d8-e22c-5410-9050-41fc7bd30f6b
STIX ID: report--79c5e9d8-e22c-5410-9050-41fc7bd30f6b
Feed Name: CyberScoop
A researcher bought and took over a Chrome extension, then pushed an automatic update that redirected a target URL (demonstrated as a harmless "Rickroll"), demonstrating how ownership changes and broad extension permissions can be silently abused to perform phishing, credential harvesting, or data exfiltration. The report warns that browser extensions are a common blind spot for organizations because updates occur silently, permission scopes are broad, and review processes may not catch repurposed or malicious code.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
