logo

SquareX Discloses “Browser Syncjacking” , a New Attack Technique that Provides Full Browser and Device Control, Putting Millions at Risk

ID: 8462a8f7-5d5f-5276-91be-b2105f5f739d

STIX ID: report--8462a8f7-5d5f-5276-91be-b2105f5f739d

Feed Name: Security Ledger

Threat Score
75/100

Date Published: 2025-01-30

Date Updated: 2026-05-05

...
...

SquareX researchers disclosed a high-impact attack called "browser syncjacking" in which malicious Chrome extensions (or hijacked legitimate ones) can silently authenticate victims into attacker-managed Google Workspace profiles, push policies, steal stored credentials, intercept and replace legitimate downloads with attacker executables that enroll the browser as managed, and use native messaging to attain full device takeover—exfiltrating data, enabling screen/camera capture, and persisting control. The attack requires minimal permissions and user interaction, evades traditional network and endpoint controls, and poses broad enterprise risk unless organizations implement browser-level visibility and controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.