Browser Plugins And Security Considerations
ID: bd570b37-76aa-57aa-a366-6235fe5127b2
STIX ID: report--bd570b37-76aa-57aa-a366-6235fe5127b2
Feed Name: Zscaler Security Research Blog
This report examines critical security weaknesses in Firefox add-ons: plugins have full access to browser and OS resources, can read HTTPS content in clear, exfiltrate credentials, modify pages and files, execute binaries, and be installed or updated silently by manipulating extension metadata (extensions.rdf/extensions.ini/extensions.cache and install.rdf updateURL). The author discusses the lack of sandboxing/permissions and how these behaviors enable credential theft and covert malware persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
