Connect with us

Hi, what are you looking for?

  1. Home
  2. /
  3. Technology
  4. /
  5. Hackers can use Chrome...

Technology

Hackers can use Chrome sync to steal passwords through extensions

Croatian information security specialist Bojan Zdrnja discovered that Google Chrome’s built-in sync function could be used by malicious extensions to steal passwords and other personal data from users’ devices.

According to a resource, an unnamed malicious extension uses the Chrome Sync function to communicate with a remote server of the attackers. During this process, they can obtain passwords and other data. This function is needed to synchronize data between users’ devices: passwords, bookmarks, browsing history, browser settings and extensions. All this is stored in the cloud on Google servers.

The malware was hiding under the Forcepoint security extension, allowing an attacker to control the infected browser. The code contained in it created a special text field to store the token keys that were synchronized with the Google cloud. There could be different data, including passwords.

“To download, read or delete these keys, the attacker only had to log in with the same Google account, but in a different Chrome browser (it could be a one-time account). After that, he could interact with the Chrome browser on the victim’s network, abusing Google’s infrastructure, ”wrote Bojan Zdrnja on the Internet Storm Center forum.

The expert advises using corporate Chrome features and group policies to control the work of installed extensions and, if necessary, block them.

Rate this product

Average rating 0 / 5. Vote count: 0

Share your thoughts on this product

Do you own this product or maybe have questions about it? Feel free to share your comments below.
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like

Mobile

Xiaomi has officially kicked off the rollout of HyperOS 3, its latest Android-16-based custom operating system, marking the next stage in the company’s long-running...

Speakers

If you’ve been searching for a speaker that doesn’t just play music but transforms your entire party into a full-blown concert experience, the JBL...

TV

TCL has long been known for making TVs that give you more for your money, and the T8C series is no exception. It combines...

TV

The TCL C9K isn’t just about size—it’s about performance. With blistering brightness, refined contrast, solid audio, and a full suite of modern features, this...

TV

The LG UA73 isn’t a showstopper, but it nails the essentials: sharp 4K, smooth streaming, and fast gaming at a fair price

Mobile

Apple’s iPhone 17 lineup is one of the most unusual in recent years. Instead of continuing with the “Plus,” Apple has introduced a brand-new...

TV

The TCL V6C series is TCL’s latest attempt to deliver affordable QLED televisions with solid performance for everyday use. Targeted at budget-conscious buyers who...

TV

The Philips OLED800 series has long been the brand’s answer to LG’s popular C-series, combining top-tier OLED picture quality with a more affordable price...

TV

If you’ve ever dreamed of turning your living room into a personal cinema, Xiaomi’s latest XXL television might be the ticket. The Xiaomi TV...

TV

8Panasonic is best known for its premium OLED televisions—designed for home cinema enthusiasts and often priced accordingly. But the new Panasonic W85B series aims...

Speakers

Samsung’s Q-Series soundbars have always been about bringing cinematic sound into the living room without the hassle of a full speaker system. The Samsung...

Headphones

Sennheiser has launched the HD 500 BAM boom microphone, transforming HD 500 series headphones into a premium gaming headset with crystal-clear voice quality and...