logo

WhatsApp Web vCard Vulnerability Exposed 200M Users

ID: e6884210-73c6-5f85-b219-603e204e24b3

STIX ID: report--e6884210-73c6-5f85-b219-603e204e24b3

Feed Name: Darknet

Threat Score
72/100

Date Published: 2015-09-09

Date Updated: 2026-05-12

...
...

**DumpBrowserSecrets** is a public post‑exploitation tool that harvests browser‑stored credentials and session tokens from major Chromium‑based browsers and Firefox by using DLL injection into a headless Chromium process to bypass App‑Bound Encryption (via the IElevator COM interface), handling DPAPI and NSS where applicable, and exporting results as structured JSON; it includes operational evasion features and is intended for red‑team assumed‑breach scenarios but can be abused by attackers to enable account takeover and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.