Malicious websites can exploit browser extension APIs to run code within the browser and steal sensitive information, such as bookmarks, browsing history, or even users' cookies.
Of course, an attacker can use cookies to capture a user's active sessions and gain access to sensitive accounts, such as email inboxes, social media profiles, or bank accounts, etc.
Furthermore, the same extension APIs (we are always talking about extensions that browsers use) can be used to trigger the download of malicious files and to store them on the user's device. This data is stored in an extension's storage, and can later be used to track users across the web.
These types of attacks are no longer theoretical, as they were recently demonstrated in a study published by Dolière Francis Somé, a researcher from the Université Côte d'Azur and INRIA, the French research institute.
Somé developed a tool and examined over 78,000 Chrome, Firefox, and Opera extensions. It was able to identify 197 extensions that allowed the exposure of internal API communication interfaces with web applications. This can give malicious websites access to data stored in a user's browser, data that should not normally be accessible.
| Chrome | Firefox | Opera | Total | |
|---|---|---|---|---|
| Extensions analyzed | 66,401 | 9,391 | 2,523 | 78,315 |
| Suspicious extensions | 3,303 | 483 | 210 | 3,996 |
| Execute code | 15 | 2 | 2 | 19 |
| Bypass SOP | 48 | 9 | 6 | 63 |
| Read cookies | 8 | – | – | 8 |
| Read browsing history | 40 | – | – | 1 |
| Read bookmarks | 37 | 1 | – | 38 |
| Get extensions installed | 33 | – | – | 33 |
| Store/retrieve data | 85 | 2 | 3 | 90 |
| Trigger downloads | 29 | 5 | 2 | 36 |
| Total unique extensions | 171 | 16 | 10 | 197 |
The French researcher says he was surprised by the results, as only 15 (or 7.61%) of the 197 extensions were development tools, a category of extensions that usually have complete control over what happens in a browser and are among the applications that should not have security vulnerabilities.
About 55% of all extensions had fewer than 1,000 installations, but over 15% had over 10,000.
Somé said he informed browser developers of his findings before releasing the research to the public in early January.
“Everyone acknowledged the problems,” Somé says. “Firefox has removed all the extensions I mentioned to them. Opera has also removed all the extensions but there are 2 more that can be exploited to trigger downloads.”.
“Chrome has also acknowledged the issue. We are still discussing together what possible steps they should take.”
The researcher also created a tool that allows users to check whether their extensions contain vulnerable APIs that can be exploited by malicious websites. The tool is web-based and hosted on this page.
To use it, you will need to copy-paste the contents of the manifest.json file of the extension you are interested in.
Watch the videos published by the researcher
If you want to read more about Somé's work: " EmPoWeb: Empowering Web Applications with Browser Extensions," you can download it as a PDF from here and here.
_______________________
- PDF 5 free online editing services
- Hacking the most commonly used tools
- VLC download online videos & convert them as you want
