September 6, 2023
Sin comentarios
The researchers explain that the problem affects numerous websites related to Google and Cloudflare, being able to obtain credentials in plain text through the extension.
This extension takes advantage of the lack of security between the components of the extension and the web page that is running. Additionally, The extension is able to bypass the password obfuscation that appears when typing in that field.
The extension, published by the researchers in the Chrome Web Store to demonstrate what happened, does not contain any malicious code, but takes advantage of the browser's own infrastructure.
Fountain: Bleeping Computer