Popular Chrome Extensions Leak API Keys, User Data via HTTP and Hardcoded Credentials

Numerous well-known Google Chrome extensions have been highlighted by cybersecurity researchers for hard-coding secrets in their code and transmitting data via HTTP, putting users’ privacy and security at risk.

A security researcher at Symantec’s Security Technology and Response team, Yuanjing Guo, stated that a number of popular extensions “unintentionally transmit sensitive data over simple HTTP.” In doing so, they reveal in plaintext browsing domains, machine IDs, operating system information, usage statistics, and even uninstall data.

The unencrypted nature of network traffic also makes it vulnerable to adversary-in-the-middle (AitM) attacks, which enable malevolent actors on the same network—like a public Wi-Fi network—to intercept and, worse, alter this data, potentially with far more dire repercussions read more about Popular Chrome Extensions Leak API Keys, User Data via HTTP and Hardcoded Credentials.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *