- Jun 9, 2013
- 6,720
Security researchers have discovered two flaws that affect the extension systems embedded in today's browsers, such as Firefox, Safari, and all the Chromium-related offshoots, such as Chrome, Opera, and others.
These flaws can be exploited by a determined attacker to expose a list of the user's installed extensions with a 100% accuracy. This information can be used to fingerprint users based on their installed extensions, to unmask anonymous users hiding behind VPN or Tor traffic, or to create advertising profiles.
First flaw affects widely used WebExtensions API
Two researchers from the University of Deusto in Spain and a researcher from Eurecom, a French research center, have discovered these flaws.
The first flaw affects the extension system used with Chromium-based browsers such as Google Chrome, Opera, the Yandex Browser, and Comodo Dragon.
The same extension system — the WebExtensions API — is also used by newer versions of Firefox, Edge, Vivaldi, and Brave. Researchers didn't test these browsers, but they said they believe them to be affected as well.
Read more. Unpatched Flaws Affect Chrome, Firefox, and Safari Browser Extension Systems
These flaws can be exploited by a determined attacker to expose a list of the user's installed extensions with a 100% accuracy. This information can be used to fingerprint users based on their installed extensions, to unmask anonymous users hiding behind VPN or Tor traffic, or to create advertising profiles.
First flaw affects widely used WebExtensions API
Two researchers from the University of Deusto in Spain and a researcher from Eurecom, a French research center, have discovered these flaws.
The first flaw affects the extension system used with Chromium-based browsers such as Google Chrome, Opera, the Yandex Browser, and Comodo Dragon.
The same extension system — the WebExtensions API — is also used by newer versions of Firefox, Edge, Vivaldi, and Brave. Researchers didn't test these browsers, but they said they believe them to be affected as well.
Read more. Unpatched Flaws Affect Chrome, Firefox, and Safari Browser Extension Systems