Please ensure Javascript is enabled for purposes of website accessibility
Hackers Exploit Chrome Extensions, Exposing Millions to 2FA Bypass Attacks
News
By News
Published 5 months ago on
December 31, 2024

Chrome extension vulnerabilities leave millions at risk of 2FA bypass attacks, with hackers targeting multiple companies. (Shutterstock)

Share

Getting your Trinity Audio player ready...

Google Chrome users face potential security risks as hackers target browser extensions to bypass two-factor authentication (2FA), as reported by Forbes.

The attacks, which began in mid-December, have compromised several companies’ Chrome extensions, potentially affecting millions of users.

Christmas Eve Attack

One notable incident involved Cyberhaven, a data attack detection company.

On Christmas Eve, a phishing attack compromised an employee’s credentials, allowing hackers to publish a malicious version of their Chrome extension. Cyberhaven CEO Howard Ting stated, “We want to share the full details of the incident and steps we’re taking to protect our customers and mitigate any damage.”

The attack bypassed 2FA by capturing session cookies, which authenticate user sessions. This method allows attackers to reuse the stolen cookies and access accounts without needing the 2FA code.

Google’s Recommendations to Mitigate Risks

To mitigate risks, Google recommends using passkeys and security keys. Vivek Ramachandran, founder of SquareX, suggests implementing server-side restrictions on risky OAuth scopes and using client-side Browser Detection-Response tools.

Google’s Chrome security team employs both automated and manual reviews to check extensions before publication on the Chrome Web Store. They also continuously monitor published extensions. Despite these efforts, some malicious extensions still slip through.

Users can protect themselves by:
1. Checking installed extensions at “chrome://extensions”
2. Running a Chrome Safety Check
3. Enabling enhanced protection mode in Safe Browsing

According to a Google spokesperson, “Google research has shown that security keys provide stronger protection against automated bots, bulk phishing attacks, and targeted attacks than SMS, app-based one-time passwords, and other forms of traditional two-factor authentication.”

Read more at Forbes

RELATED TOPICS:

DON'T MISS

What Are Fresno Real Estate Experts Predicting for 2025 and Beyond?

DON'T MISS

First California EV Mandates Hit Automakers This Year. Most Are Not Even Close

DON'T MISS

Fresno Man, a Repeat DUI Offender, Sentenced to 15 Years to Life for Teen’s Death

DON'T MISS

Jewish Student Who Took on Harvard in Court Ends Lawsuit

DON'T MISS

Oakhurst Man Charged for Fresno Stalking, Child Exploitation

DON'T MISS

Trump Announces $14.5 Billion Etihad Commitment With Boeing, GE

DON'T MISS

Denver Air Traffic Briefly Lost Communications on Monday, FAA Says

DON'T MISS

Fresno Shut Out Of $200M for Downtown Projects by State Budget

DON'T MISS

Feds Charge Two Men in Email Scam Pulled on Fresno County

DON'T MISS

Fresno Officials Urge Parole Board to Deny Release of Convicted ‘Tower Rapist’

DON'T MISS

Clovis Mayor’s Breakfast Hot Topics: Elections, Measure C, ‘Way of Life’

DON'T MISS

Ben & Jerry’s Founder Arrested at Senate Hearing After Protesting War in Gaza

UP NEXT

Jewish Student Who Took on Harvard in Court Ends Lawsuit

UP NEXT

Oakhurst Man Charged for Fresno Stalking, Child Exploitation

UP NEXT

Trump Announces $14.5 Billion Etihad Commitment With Boeing, GE

UP NEXT

Denver Air Traffic Briefly Lost Communications on Monday, FAA Says

UP NEXT

Fresno Shut Out Of $200M for Downtown Projects by State Budget

UP NEXT

Feds Charge Two Men in Email Scam Pulled on Fresno County

UP NEXT

Fresno Officials Urge Parole Board to Deny Release of Convicted ‘Tower Rapist’

UP NEXT

Clovis Mayor’s Breakfast Hot Topics: Elections, Measure C, ‘Way of Life’

UP NEXT

Ben & Jerry’s Founder Arrested at Senate Hearing After Protesting War in Gaza

UP NEXT

Trump Navigates Iran Nuclear Talks. Should US Insist on Zero Enrichment?

Trump Announces $14.5 Billion Etihad Commitment With Boeing, GE

6 hours ago

Denver Air Traffic Briefly Lost Communications on Monday, FAA Says

6 hours ago

Fresno Shut Out Of $200M for Downtown Projects by State Budget

6 hours ago

Feds Charge Two Men in Email Scam Pulled on Fresno County

6 hours ago

Fresno Officials Urge Parole Board to Deny Release of Convicted ‘Tower Rapist’

8 hours ago

Clovis Mayor’s Breakfast Hot Topics: Elections, Measure C, ‘Way of Life’

8 hours ago

Ben & Jerry’s Founder Arrested at Senate Hearing After Protesting War in Gaza

9 hours ago

Trump Navigates Iran Nuclear Talks. Should US Insist on Zero Enrichment?

9 hours ago

WNBA Set To Tipoff Season With Teams Looking To Challenge For Title

9 hours ago

CA Gov. Gavin Newsom Tries to Rebrand Himself Ahead of Potential Presidential Run

9 hours ago

Fresno Man, a Repeat DUI Offender, Sentenced to 15 Years to Life for Teen’s Death

A Fresno man with a prior DUI conviction was sentenced Thursday to 15 years to life in state prison for causing a 2022 crash that killed a 1...

4 hours ago

4 hours ago

Fresno Man, a Repeat DUI Offender, Sentenced to 15 Years to Life for Teen’s Death

People sit on the grass at the campus of Harvard University in Cambridge, Massachusetts, U.S., April 15, 2025. REUTERS/Faith Ninivaggi/File Photo
5 hours ago

Jewish Student Who Took on Harvard in Court Ends Lawsuit

6 hours ago

Oakhurst Man Charged for Fresno Stalking, Child Exploitation

U.S. President Donald Trump meets United Arab Emirates President Sheikh Mohamed bin Zayed Al Nahyan, at Qasr Al Watan, in Abu Dhabi, United Arab Emirates, May 15, 2025. REUTERS/Amr Alfiky
6 hours ago

Trump Announces $14.5 Billion Etihad Commitment With Boeing, GE

The air traffic control tower is seen from the Denver International Airport terminal, as a Delta flight sits at the gate, in Denver, Colorado, U.S., May 15, 2025. REUTERS/Megan Varner
6 hours ago

Denver Air Traffic Briefly Lost Communications on Monday, FAA Says

6 hours ago

Fresno Shut Out Of $200M for Downtown Projects by State Budget

6 hours ago

Feds Charge Two Men in Email Scam Pulled on Fresno County

8 hours ago

Fresno Officials Urge Parole Board to Deny Release of Convicted ‘Tower Rapist’

Help continue the work that gets you the news that matters most.

Search

Send this to a friend