Chrome Extension Vulnerabilities: Millions at Risk
ID: 0a03f18b-7200-5a55-bea0-8642fe229e1e
STIX ID: report--0a03f18b-7200-5a55-bea0-8642fe229e1e
Feed Name: securityonline.info
Rebora Security Research reports two critical Chrome extension vulnerabilities—MaXSS in MaxAI and Spyder in SiderAI—that allow visiting webpages to send unsanitized messages or synthesize user actions, enabling arbitrary command execution, hidden tab creation, screenshot capture, chat-history theft and data exfiltration; both extensions have broad deployment (millions of installs) and, according to the report, remain unpatched, so users are advised to remove them to prevent account takeover and data leakage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
