logo

Microsoft Investigates IE CSS Cross-Origin Theft Vulnerability

ID: 13f84da4-02b6-51ad-b858-d0eddb06a59e

STIX ID: report--13f84da4-02b6-51ad-b858-d0eddb06a59e

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-09-08

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a public post‑exploitation tool that extracts credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS decryption). The tool uses headless Chromium spawning, Early Bird APC DLL injection, and the IElevator COM interface to decrypt app_bound_encrypted_key for Chromium-based browsers, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is intended for red-team/assumed‑breach testing but represents a high‑risk capability for credential theft and cloud account takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.