The researchers explain that the problem affects numerous websites related to Google and Cloudflare, being able to obtain credentials in plain text through the extension.

This extension takes advantage of the lack of security between the components of the extension and the web page that is running. Additionally, The extension is able to bypass the password obfuscation that appears when typing in that field.

The extension, published by the researchers in the Chrome Web Store to demonstrate what happened, does not contain any malicious code, but takes advantage of the browser's own infrastructure.

Fountain: Bleeping Computer


Leave a Reply

Your email address will not be published. Required fields are marked *

More news
An error in Lenovo ID allows unauthorized access to Dropbox
Read more »
Expuestos los datos de casi 9 millones de pasajeros de aeropuertos británicos
Read more »
A cyberattack against the French tax authority is confirmed
Read more »
Identity thefts of content creators are proliferating on TikTok
Read more »
Un ciberataque compromete los datos de Liechtenstein
Read more »