HomeSecurityAttack on Chrome extensions allows them to be disabled

Attack on Chrome extensions allows them to be disabled

Security researcher Mathias Karlsson reports that attackers can remove Google Chrome extensions, such as the popular HTTPS Everywhere, without users of the popular application having to do anything other than visit a website.website-security Chrome

Karlsson (@avlidienbrunn) reports that the vulnerability exists in the latest stable version of Chrome and allows extensions to be compromised without requiring any significant intervention.

“After a few hours of analysis I was able to disable HTTPS Everywhere just by viewing an HTML page,” says Karlsson.

“In fact, I was able to disable any extension without user interaction.”

Karlsson published a PoC demonstrating disabling HTTPS Everywhere.

The flaw affects all users who do not configure Chrome's automatic updates.

Extensions can be corrupted when websites attempt to access the Chrome extension URI handler. A malicious link that leads to a specially crafted page that pings the feature in question is enough to carry out the attack.

Google had blocked most Chrome URI requests for extensions, but it appears that ping still works.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS