The researchers explain that the problem affects numerous websites related to Google and Cloudflare, being able to obtain credentials in plain text through the extension.

This extension takes advantage of the lack of security between the components of the extension and the web page that is running. Additionally, The extension is able to bypass the password obfuscation that appears when typing in that field.

The extension, published by the researchers in the Chrome Web Store to demonstrate what happened, does not contain any malicious code, but takes advantage of the browser's own infrastructure.

Fountain: Bleeping Computer


Leave a Reply

Your email address will not be published. Required fields are marked *

More news
This is how the use of AI in cybercrime has evolved
Read more »
Skoda confirms a breach on its web portal
Read more »
data of almost 200.000 Zara users are exposed
Read more »
Vimeo sufre una brecha de datos
Read more »
Booking.com suffers a data exfiltration of bookings
Read more »