Security News Unpatched Flaws Affect Chrome, Firefox, and Safari Browser Extension Systems

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Security researchers have discovered two flaws that affect the extension systems embedded in today's browsers, such as Firefox, Safari, and all the Chromium-related offshoots, such as Chrome, Opera, and others.

These flaws can be exploited by a determined attacker to expose a list of the user's installed extensions with a 100% accuracy. This information can be used to fingerprint users based on their installed extensions, to unmask anonymous users hiding behind VPN or Tor traffic, or to create advertising profiles.

First flaw affects widely used WebExtensions API
Two researchers from the University of Deusto in Spain and a researcher from Eurecom, a French research center, have discovered these flaws.

The first flaw affects the extension system used with Chromium-based browsers such as Google Chrome, Opera, the Yandex Browser, and Comodo Dragon.

The same extension system — the WebExtensions API — is also used by newer versions of Firefox, Edge, Vivaldi, and Brave. Researchers didn't test these browsers, but they said they believe them to be affected as well.

Read more. Unpatched Flaws Affect Chrome, Firefox, and Safari Browser Extension Systems
 

ispx

Level 13
Verified
Well-known
Jun 21, 2017
616
i guess if you ain't got no extensions you are unaffected ;)

Researchers didn't test these browsers, but they said they believe them to be affected as well.

there should be no gray area when it comes to matters of exploits & infections, either black / white, safe / unsafe, as simple as that.

researchers should have concrete results & only make claims when they are dead sure & not expect people to go by what, " they believe ".
 

Elpibe

Level 3
Verified
Sep 26, 2015
126
I dont undestand how they can unmask a VPN user. If someone exploit the extension and see the list of what i have in the browser, and im using a Vpn, the connection is encrypted they shouldnt be able to fingerprint/know what im doing, right?
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
browsers with MBAE HMPA protecting the extensions?
It would be a disappointment wich a pirate violated our browser that is protected.
Those anti-exploit apps are mainly focused on preventing something from breaking out of the browser and sticking its fingers into other areas of the system. But here, the exploit is within the browser itself.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top