Malicious Chrome Extensions Skate Past Google's Updated Security
ID: 2202a85f-ce9f-5852-b7e4-3cf8d3a173c5
STIX ID: report--2202a85f-ce9f-5852-b7e4-3cf8d3a173c5
Feed Name: Dark Reading
SquareX researchers demonstrated at DefCon 32 that malicious Chrome extensions can circumvent Google’s Manifest V3 safeguards to steal live video feeds, redirect users to phishing pages, manipulate GitHub access, and exfiltrate cookies and browsing history using overly broad host permissions. The article argues MV3’s permission model remains too permissive, while Google highlights enterprise controls, admin alerts, and risk assessment tools (CRXcavator, Spin.AI) amid the MV2-to-MV3 migration. Organizations are advised to audit installed extensions, limit permissions, and improve visibility and control over browser extensions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
