Malicious Chrome extensions can spoof password managers in new attack
ID: d13a5ee6-c766-5abb-8ac1-66aa15422722
STIX ID: report--d13a5ee6-c766-5abb-8ac1-66aa15422722
Feed Name: Bleeping Computer
SquareX Labs details a practical polymorphic Chrome extension attack that identifies installed extensions, disables or hides a targeted one, and then impersonates it (e.g., 1Password) to present realistic phishing prompts that capture user credentials before reverting to its original state. The method relies on the chrome.management API and UI deception, with no current Chrome defenses to block abrupt icon/HTML changes. Researchers recommend Google add safeguards or user notifications to mitigate this impersonation risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
