Security researcher Mathias Karlsson reports that attackers can remove Google Chrome extensions, such as the popular HTTPS Everywhere, without users of the popular application having to do anything other than visit a website.
Karlsson (@avlidienbrunn) reports that the vulnerability exists in the latest stable version of Chrome and allows extensions to be compromised without requiring any significant intervention.
“After a few hours of analysis I was able to disable HTTPS Everywhere just by viewing an HTML page,” says Karlsson.
“In fact, I was able to disable any extension without user interaction.”
Karlsson published a PoC demonstrating disabling HTTPS Everywhere.
The flaw affects all users who do not configure Chrome's automatic updates.
Extensions can be corrupted when websites attempt to access the Chrome extension URI handler. A malicious link that leads to a specially crafted page that pings the feature in question is enough to carry out the attack.
Google had blocked most Chrome URI requests for extensions, but it appears that ping still works.
