HomeSecurityHackers can compromise Chromium browsers on Windows

Hackers can compromise Chromium browsers on Windows

Chromium-based browsers, such as Chrome, Edge, and Brave, manage installed extensions through JSON preference files stored in %AppData%\Google\User Data\Default\Preferences (for domain-joined machines) or in Secure Preferences (for standalone systems).

See also: Chrome: Critical type confusion vulnerability analysis

Chromium
Hackers can compromise Chromium browsers on Windows

Synacktiv 's research indicates that by directly modifying these files, attackers can make the browser load any extensions without user consent or Chrome Web Store involvement .

A successful breach involves three technical prerequisites: pre-computing the extension ID, generating valid Message Control Codes (MACs) for both the extension registration and the developer_mode flag, and bypassing enterprise policy checks.

Extension IDs are deterministically derived from the extension's public key or installation path via a SHA-256 hash truncated to 32 hex characters and mapped to a custom alphabet (a–p). Chromium's integrity checks use an HMAC seeded with a static value extracted from resources.pak, specifically resource file 146, to sign JSON key signatures.

See also: Google fixes new zero-day vulnerability in Chrome

Hackers can compromise Chromium browsers on Windows
Hackers can compromise Chromium browsers on Windows

Attackers reverse engineer this HMAC algorithm to compute valid MACs for extensions.settings. and extensions.developer_mode, allowing their backdoor extension to be silently registered. Enterprise environments typically deploy GPOs to allow or block extensions via policies such as ExtensionInstallAllowlist and ExtensionInstallBlocklist.

Windows enforces policies in the order LSDOU. Although Chrome policies are located under HKCU\Software\Policies\Google\Chrome, a local administrator can delete or modify the registry entries, removing the allow or block lists to bypass policy enforcement.

By exploiting these techniques, malicious actors can develop extensions that intercept network traffic, steal session cookies, run service workers in the background, and inject content scripts into targeted web pages.

See also: Chrome blocks browser launch at administrator level

Hackers can compromise Chromium browsers on Windows

Protection requires monitoring for unauthorized changes to preference files, validating registry policy integrity, and detecting anomalous extension entries. Without such detection mechanisms, “phantom extensions” offer a hidden, persistent path for enterprise-level data extraction and lateral movement

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS