The WebEx Chrome Extension Vulnerability and the Power of Virtual Patching
ID: 7bc030e6-7c8e-5702-ac1c-d49b9b9caf4c
STIX ID: report--7bc030e6-7c8e-5702-ac1c-d49b9b9caf4c
Feed Name: Cato Networks
Threat Score
A WebEx Chrome extension vulnerability enables drive-by remote code execution by triggering Native Messaging with a specific "magic" URL pattern; a public proof-of-concept demonstrates executing commands (e.g., calc.exe). Cisco patched the extension, but many users remain exposed until they restart/update Chrome; recommended mitigations include updating the extension and applying network-level virtual patching (URL/IPS filters or SWG blocks for the magic pattern).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
