Target Industry
Indiscriminate, opportunistic targeting.
Overview
A new threat involving malicious Chrome and other Chromium-based browser extensions has been discovered. This flaw allows malicious extensions to impersonate other extensions, enabling threat actors to steal sensitive information from users. The attack is called “polymorphic” because the extensions can change their form to avoid detection. This poses a critical security risk for users of major browsers like Chrome and Edge.
Impact
The impact of this new threat involving polymorphic browser extensions is critical. Malicious extensions can steal sensitive information, such as passwords, financial details, and personal data. Users may lose trust in browser extensions, even legitimate ones, due to the risk of impersonation.
The ability of these extensions to change form makes them difficult to detect and remove, posing ongoing security risks. Users may even suffer financial losses if their banking or crypto wallet information is compromised.
Exploitation
The exploitation of polymorphic browser extensions involves several steps. First, the user unknowingly installs a malicious extension, often disguised as a legitimate tool. After it is installed, the extension scans the browser for other installed extensions and changes its appearance to mimic a legitimate one.
These could be password managers, banking applications, or digital wallets. It may temporarily disable the legitimate extension, tricking users into interacting with the fake one. When users enter their credentials into the fake extension, the information is captured and sent to the threat actor. Stored passwords can be lost with just one click on a malicious prompt.
Containment, Mitigations & Remediations
To mitigate the threat of polymorphic browser extensions, users should be cautious when installing extensions and only download them from trusted sources. Regularly review and update installed extensions and remove any that are no longer needed. Browser developers should enhance security protocols to detect and block malicious extensions. Additionally, using robust security software can help identify and prevent such threats. Educating users about the risks and signs of malicious extensions is also crucial in reducing the likelihood of exploitation.
Cyber News reports that there is currently no patch to remedy this vulnerability because it is an inherent function of the Chrome browser. According to cyber security company SquareX, this is not a software problem as no vulnerability exists.
Threat Landscape
In a recent campaign involving similar malicious extensions at least 300,000 users across Google Chrome and Microsoft Edge were affected. Given the widespread use of these browsers, millions of users could potentially be at risk if such threats continue to evolve and spread. Major browsers like Chrome and Edge are affected, creating a vast attack vector.
Threat Groups
The specific threat group behind this has not been publicly identified at the time of writing.
Further Information













