Chrome: Thousands of extensions play with user security 1

Chrome: Thousands of extensions play with user security

With Google Chrome 91 just released, computer security researchers from the CISPA Helmholtz Center institute decided to examine 186,000 extensions of the Chrome Web Store. The purpose of the maneuver? Check if these extensions disable HTTP connection security headers.

You see, security HTTP headers are specially designed to block many cyber attacks like sending corrupted data or exploiting various vulnerabilities. For example, the HSTS (HTTP Strict Transport Security) header uses data encryption (SSL certificate) to prevent malicious interception of your data during browsing.

Also read: Chrome 91 improves file copy-paste and form design on Windows 10

2485 extension removes basic HTTP headers

Another example, the Public Key Pinning header protects you against unauthorized certificate issuance, thus preventing Man-in-the-Middle attacks that are specifically used to steal access credentials or other sensitive data. However, and according to the results obtained by researchers from the CISPA Helmhotz Center institute, 2485 extension removes at least one of the following four HTTP headers :

  • HSTS protocol
  • XFO (X-Frame options) that protect a site’s visitors against the click-through technique (allows the user to be redirected to different content than the one selected by the user)
  • XCTO (X Content-Type Options) which protects the server from attempts to sniff MIME types (allows an attacker to perform certain dangerous actions against the site or user)
  • CSP (Content Security Policy) that prevents an attacker from placing malicious scripts on a site’s homepage

Cherries on the cake 533 extensions output these four headers simultaneously. As the researchers pointed out, it doesn’t have to be a profession that will harm the user’s security, the developers of these extensions prefer to do without these headers to offer more functionality in their software.

But in the end the result remains the same, drastically increased risk of cyberattack for users of these Google Chrome extensions. As a reminder, Google Chrome 90 has recently suffered from numerous bugs on computers running Windows 10. Google quickly outlined the procedure to follow to fix the issue.

Source : Record

Support our work ❤️

If you enjoyed this article, consider leaving a tip to help us keep publishing great content.

Secure payment on PayPal
Moyens I/O Staff is a team of expert writers passionate about technology, innovation, and digital trends. With strong expertise in AI, mobile apps, gaming, and digital culture, we produce accurate, verified, and valuable content. Our mission: to provide reliable and clear information to help you navigate the ever-evolving digital world. Discover what our readers say on Trustpilot.