HomeinetBrowsers: Data leak across all platforms

Browsers: Data leak across all platforms

Security researchers have discovered flaws (PDF) in the extension systems of all modern browsers that can be exploited by attackers to enumerate all installed browser extensions.

The attack affects all modern browsers. Researchers have managed to confirm it in all browsers that are based on Chromium and believe it also affects other browsers such as Firefox or Edge that use the same extension system. The additional system for Firefox add-ons is also vulnerable to the attack.browsers

The Chromium-based browsers affected are Google Chrome, Yandex, and Opera, and Firefox-based browsers such as Firefox or Pale Moon, and Microsoft Edge.

All browsers protect extension data from the websites they visit. However, we have seen that websites use various techniques to collect data from browsers.

Security researchers have discovered a method that helps them enumerate the installed browser extensions even in the latest versions of browsers.

The “timing side-channel attack” or “timing side-channel attack” can be used to enumerate the installed browser extensions by monitoring the browser’s response from its access to system resources.

When a website requests access to a resource of an extension in the browser, the browser must perform two checks: one to determine whether the extension exists and another to determine whether the resource the website wants to access is publicly available.

By monitoring the response, attackers may be able to identify the reason behind the denial of a request. The website measures the time it takes for a request to return from a fake extension and the time a real extension needs.

By comparing the time, the installed extensions are revealed. According to the researchers, the accuracy of the method reaches 100%.

The attack uses extension identifiers and some code. Researchers already have about 10000 extension identifiers for Chrome and Firefox. Thus they can pinpoint extensions precisely by comparing the identifiers.

The “real” attackers could use this information for fingerprinting or for targeted attacks against specific browser extensions.

Since all these attacks are based on scripts, any blocking of the scripts can protect you from the attack.

Update: After a conversation we had on Facebook with a friend of SecNews, we thought we'd clarify that Apple's browser is also affected: it's affected by a URI leakage in Safari's extension model.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS