HomeSecurityChrome extension steals passwords from websites

Chrome extension steals passwords from websites

A team of researchers from the University of Wisconsin-Madisonhas published an extension to the Chrome Web Store that can extract plain text passwords from source code .

See also: Bing Chat: Available in Google Chrome for all desktop users

Chrome extension

After an analysis of text input fields in web browsers, it emerged that the coarse-grained permission model violates the principles of least privilege and full mediation, which are used to support Chrome extensions.

Additionally, researchers discovered that many websites with millions of visitors, including some Google and Cloudflare, store passwords in plain text in the HTML source code of their web pages, allowing extensions to retrieve them.

Researchers explain that the problem concerns the systemic practice of providing browser extensions, which allows access to potentially sensitive information, such as user input fields.

Considering the lack of a secure boundary between the extension and a website's elements, the former has unlimited access to data visible in the source code and can extract any content from it.

Additionally, the extension can abuse the DOM API to directly extract input information as the user enters it, bypassing any restrictions imposed by the website to protect sensitive data and retrieving the information programmatically.

The Manifest V3, introduced by Google Chrome and adopted by most browsers this year, aims to limit API abuse. It prohibits extensions from retrieving code from remote servers, in order to limit the possibility of detection and prevent arbitrary code execution via evaluation commands. However, as the researchers explain, Manifest V3 does not establish a security boundary between extensions and web pages. Therefore, the problem arising from content scripts remains unsolved.

See also: Chrome is testing an option to enable the address bar at the bottom on iOS

To test the Google Web Store review process, the researchers decided to create a Chrome extension capable of password-snatching attacks and try to upload it to the platform

passwords

The researchers developed a helper extension, based on GPT, that can:

  • Capture the HTML source code when the user attempts to connect to a page via a regex.
  • It uses CSS selectors to select target input fields and extract user inputs using the '.value' function.
  • Performs element replacement to replace ambiguous JS-based fields with insecure password fields.

This led to the extension being accepted after review and included in the Google Chrome Web Store. As a result, the security checks failed to detect any threat.

The team followed ethical standards to ensure that no real data was collected or used. They disabled the data acquisition server and kept only the targeting server for the data active.

Additionally, the extension is set to “unpublished” and can change this status at any time to prevent excessive downloads. Immediately after its approval, it was removed from the store.

See also: Google Chrome: Will warn about removing extensions that are malware

A Google spokesperson confirmed that they are looking into the issue and highlighted it in the Chrome Extension Security FAQ . They do not consider access to password fields to be a security issue when the appropriate permissions are properly obtained

Chrome extensions are one of the key factors that enhance the functionality of the browser. However, as the above research shows, they can also expose users to significant security risks. The fact that a Chrome extension can retrieve passwords from a website's source code demonstrates the need for enhanced security practices and better extension controls.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS