logo

Adobe Scrambling To Fix Another Serious PDF Flaw

ID: 936479c0-64c3-55c5-a4ce-24423219a699

STIX ID: report--936479c0-64c3-55c5-a4ce-24423219a699

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-08-09

Date Updated: 2026-05-13

...
...

DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and session tokens from major Chromium-based browsers and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL that leverages the IElevator COM interface (via Early Bird APC injection) to decrypt the app_bound_encrypted_key; for DPAPI and NSS-based stores it retrieves and decrypts secrets accordingly. The report covers extracted data types, evasion techniques, an operational attack scenario, detection opportunities, and mitigation recommendations for enterprise environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.