Security experts have unveiled that cybercriminals have been leveraging the Chrome extension framework to orchestrate prolonged attacks, pilfering user data via browser extensions laced with malicious code. This has impacted tens of thousands of devices. Even after an extension is removed from the app store, users remain vulnerable if they fail to manually review and modify their browser settings. These malicious extensions frequently masquerade as handy tools, such as AI assistants and VPN services. By acquiring developer permissions through phishing schemes, they embed malicious code to pilfer sensitive data, including user Cookies and access tokens. Exploiting the elevated privileges inherent in browser extensions, attackers can access cookies across different domains, inject harmful scripts, track user activities, and even remotely manipulate browsers. Users are urged to promptly inspect and remove any suspicious extensions, reset passwords for critical accounts, activate two-factor authentication, keep their browsers and operating systems up-to-date, and refrain from installing extensions from unverified sources.
