logo

Malicious Chrome Extensions Skate Past Google's Updated Security

ID: 2202a85f-ce9f-5852-b7e4-3cf8d3a173c5

STIX ID: report--2202a85f-ce9f-5852-b7e4-3cf8d3a173c5

Feed Name: Dark Reading

Date Published: 2024-10-04

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

SquareX researchers demonstrated at DefCon 32 that malicious Chrome extensions can circumvent Google’s Manifest V3 safeguards to steal live video feeds, redirect users to phishing pages, manipulate GitHub access, and exfiltrate cookies and browsing history using overly broad host permissions. The article argues MV3’s permission model remains too permissive, while Google highlights enterprise controls, admin alerts, and risk assessment tools (CRXcavator, Spin.AI) amid the MV2-to-MV3 migration. Organizations are advised to audit installed extensions, limit permissions, and improve visibility and control over browser extensions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.