Добавить новость
News in English
Новости сегодня

Новости от TheMoneytizer

Billions of Google Chrome users warned to delete ALL popular extensions right now – experts explain why

GOOGLE Chrome users have been warned over sneaky browser extensions that can see everything you do on the web.

Whether it’s an ad-blocker, spell checker or PDF scanner – browser extensions possess more powers than many regular apps on your smartphone.

In 2019, multiple malicious Chrome extensions were used to intercept people logging into popular sites such as Facebook
Getty

Extensions can use the “chrome.webRequest” API, which is regarded as a “critical” risk, experts told CyberNews.

Even popular browser extensions that are considered safe, and downloaded directly from the Chrome Web Store, can put your passwords and data at risk.

Oren Koren, co-founder of cybersecurity firm Veriti, explained: “Everybody nowadays uses the ad-block extension, and it’s massively using the webRequest function.

“This function allows it to intercept five types of data.”

  1. http:// ­- risk of browsing data interception;
  2. https:// – risk of encrypted browsing data interception;
  3. ftp:// – risk of exposing login credentials and unauthorized file access (directory listing of the FTP server, username and password passed in the login stage, the ability to track and download files);
  4. file:// – risk of disclosing sensitive local files or internal resources (specific internal or external file paths that only the owner has);
  5. ws:// – risk for web services that can compromise an organization’s content

Essentially, your ad-blocker can see all the content you send over the web, including your login credentials and the files you download, Koren warned.

And that’s just the ‘safe’ ones.

The internet is riddled with browser extensions that were built for malicious purposes – just like how the Google Play Store can accidentally host spyware apps.

This is because it takes vast amount of time for Google to analyse each app and pull them off the market.

Patrick Harr, CEO of cybersecurity company SlashNext, urged consumers to think beyond phishing scams and actually examine how many permissions they have granted their browser extensions.

“In the current threat landscape, malicious browser extensions are very common, especially as a tool for delivering ransomware,” he said.

“We usually think of ransomware as starting in a phishing email, which certainly is a leading point of origination.

“But bad actors are also skilled at leveraging malicious browser extensions to steal user credentials as a first step in their ultimate goal of deploying ransomware.”

If you really want to have your ad-blocker, translator, or whichever popular extension you’re into – make sure it is from reputable developer and look over exactly what data it collects.

Cyber crooks can use the ‘chrome.webRequest’ API to inject viruses into your PC or lead you to phishing pages, according to Oleksii Yasynskyi, engineering manager of Malware Lab at Moonlock.

While other extensions can be used for spying and collecting personal data, he said.

For example, in 2018, an extension used the “chrome.webRequest” API to steal credit card information.

Then in 2019, multiple malicious Chrome extensions were used to intercept people logging into popular sites such as Facebook and Google.

Best Phone and Gadget tips and hacks

Looking for tips and hacks for your phone? Want to find those secret features within social media apps? We have you covered...

Get all the latest WhatsApp, Instagram, Facebook and other tech gadget stories here.


We pay for your stories! Do you have a story for The Sun Online Tech & Science team? Email us at tech@the-sun.co.uk

Читайте на сайте


Smi24.net — ежеминутные новости с ежедневным архивом. Только у нас — все главные новости дня без политической цензуры. Абсолютно все точки зрения, трезвая аналитика, цивилизованные споры и обсуждения без взаимных обвинений и оскорблений. Помните, что не у всех точка зрения совпадает с Вашей. Уважайте мнение других, даже если Вы отстаиваете свой взгляд и свою позицию. Мы не навязываем Вам своё видение, мы даём Вам срез событий дня без цензуры и без купюр. Новости, какие они есть —онлайн с поминутным архивом по всем городам и регионам России, Украины, Белоруссии и Абхазии. Smi24.net — живые новости в живом эфире! Быстрый поиск от Smi24.net — это не только возможность первым узнать, но и преимущество сообщить срочные новости мгновенно на любом языке мира и быть услышанным тут же. В любую минуту Вы можете добавить свою новость - здесь.




Новости от наших партнёров в Вашем городе

Ria.city
Музыкальные новости
Новости России
Экология в России и мире
Спорт в России и мире
Moscow.media






Топ новостей на этот час

Rss.plus





СМИ24.net — правдивые новости, непрерывно 24/7 на русском языке с ежеминутным обновлением *