Attacking Chrome extensions allows you to disable them

Security investigator Mathias Karlsson reports that attackers can remove Google Chrome extensions, such as the popular HTTPS Everywhere, χωρίς να χρειάζεται να κάνουν κάτι οι χρήστες της δημοφιλούς εφαρμογής, από το να επισκεφτούν μια .website-security Chrome

Karlsson (@avlidienbrunn) reports that vulnerability exists in the latest stable version of Chróme and allows extensions to work without substantial intervention being required.

“After a few hours of analysis I managed to disable it  μόνο με την προβολή μιας s HTML," says Karlsson.

"In fact, I was able to disable any extension without user interaction."

Karlsson published a PoC which shows off the HTTPS Everywhere.

The flaw affects all users who do not configure the automatics of Chrome.

Extensions can be destroyed when web pages attempt to access the Chrime extension URI handler. A malicious link that leads to a specially configured page that sends ping requests to that feature is enough to perform the attack.

Google had blocked most Chrome URI requests for extensions, but it seems that ping still works.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).