logo

Google Leaves Android Users Vulnerable To WebView Exploit

ID: b8a61acc-78a3-5106-b0a8-2aaa50ebf44b

STIX ID: report--b8a61acc-78a3-5106-b0a8-2aaa50ebf44b

Feed Name: Darknet

Threat Score
75/100

Date Published: 2015-01-14

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (passwords, cookies, OAuth tokens, credit cards, autofill, history) from Chromium-based and Firefox browsers; it implements an App-Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL to use the IElevator COM interface, handles DPAPI for Opera-based browsers, and uses NSS decryption for Firefox. The report details its evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), output format, attack scenario, detection opportunities, and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.