New Syncjacking attack hijacks devices using Chrome extensions
ID: 7fbdcecf-9c73-5477-ab5a-9fe3707a2ffd
STIX ID: report--7fbdcecf-9c73-5477-ab5a-9fe3707a2ffd
Feed Name: Bleeping Computer
SquareX researchers disclosed "Browser Syncjacking," a stealthy multi-stage attack where a malicious Chrome extension logs victims into attacker-managed Google Workspace profiles, prompts them to enable Chrome Sync, and then uses the synced profile plus Chrome Native Messaging to access passwords, Drive data, install further extensions or executables, execute commands, and potentially control the device; the attack requires minimal permissions and little user interaction and was demonstrated via a Chrome Web Store extension and social engineering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
