Attacking Chrome extensions allows you to disable them

Security researcher Mathias Karlsson reports that attackers can remove its extensions , like the popular one HTTPS Everywhere, without users of the popular app having to do anything other than visit a web.website-security Chrome

Karlsson (@avlidienbrunn) reports that the vulnerability exists in the last stable of Chrome and allows intervention in extensions without requiring substantial intervention.

"After a few hours of analysis, I was able to turn off HTTPS Everywhere just by viewing an HTML page," says Karlsson.

"In fact, I was able to disable any extension without user interaction."

Karlsson published a PoC which shows off the HTTPS Everywhere.

The flaw affects all users who do not set up Chrome automatic updates.

Οι επεκτάσεις μπορούν να καταστραφούν όταν οι ιστοσελίδες επιχειρούν να αποκτήσουν πρόσβαση στο Chrοme extension URI handler. Ένα κακόβουλο link που οδηγεί σε μια ειδικά διαμορφωμένη σελίδα που στέλνει ping στο εν λόγω χαρακτηριστικό, είναι αρκετό για την πραγματοποίηση της επίθεσης.

Google had blocked most Chrome URI requests for extensions, but it seems that ping still works.

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by Dimitris

Dimitris hates on Mondays .....

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).