Please ensure Javascript is enabled for purposes of website accessibility

7.3 Magnitude Earthquake Strikes Off Alaska Coast. No Danger to California

5 hours ago

Federal Immigration Crackdown Threatens California’s Historic Housing Reforms

9 hours ago

US House Clears Procedural Hurdle on Cryptocurrency Legislation

10 hours ago

Fresno County Lifts Evacuation Order for Max Fire Near Pine Flat Lake

11 hours ago

Newsom Calls Trump a ‘Son of a B***h’ Over ICE Raids and Guard Deployment

11 hours ago

Trump Indicated to Republican Lawmakers He Will Fire Fed’s Powell, CBS Reports

12 hours ago

Wall Street Steadies as Investors Assess Inflation Data, Earnings

13 hours ago

Trump Administration Sued by US States for Cutting Disaster Prevention Grants

13 hours ago

Open Mic Contest Offers Fans a Chance to Perform at Outside Lands 2025

14 hours ago

PBS and NPR Mount Last-Ditch Fight to Save Federal Funding

2 days ago
Hackers Exploit Chrome Extensions, Exposing Millions to 2FA Bypass Attacks
News
By News
Published 7 months ago on
December 31, 2024

Chrome extension vulnerabilities leave millions at risk of 2FA bypass attacks, with hackers targeting multiple companies. (Shutterstock)

Share

Getting your Trinity Audio player ready...

Google Chrome users face potential security risks as hackers target browser extensions to bypass two-factor authentication (2FA), as reported by Forbes.

The attacks, which began in mid-December, have compromised several companies’ Chrome extensions, potentially affecting millions of users.

Christmas Eve Attack

One notable incident involved Cyberhaven, a data attack detection company.

On Christmas Eve, a phishing attack compromised an employee’s credentials, allowing hackers to publish a malicious version of their Chrome extension. Cyberhaven CEO Howard Ting stated, “We want to share the full details of the incident and steps we’re taking to protect our customers and mitigate any damage.”

The attack bypassed 2FA by capturing session cookies, which authenticate user sessions. This method allows attackers to reuse the stolen cookies and access accounts without needing the 2FA code.

Google’s Recommendations to Mitigate Risks

To mitigate risks, Google recommends using passkeys and security keys. Vivek Ramachandran, founder of SquareX, suggests implementing server-side restrictions on risky OAuth scopes and using client-side Browser Detection-Response tools.

Google’s Chrome security team employs both automated and manual reviews to check extensions before publication on the Chrome Web Store. They also continuously monitor published extensions. Despite these efforts, some malicious extensions still slip through.

Users can protect themselves by:
1. Checking installed extensions at “chrome://extensions”
2. Running a Chrome Safety Check
3. Enabling enhanced protection mode in Safe Browsing

According to a Google spokesperson, “Google research has shown that security keys provide stronger protection against automated bots, bulk phishing attacks, and targeted attacks than SMS, app-based one-time passwords, and other forms of traditional two-factor authentication.”

Read more at Forbes

RELATED TOPICS:

DON'T MISS

What Are Fresno Real Estate Experts Predicting for 2025 and Beyond?

DON'T MISS

First California EV Mandates Hit Automakers This Year. Most Are Not Even Close

DON'T MISS

Trump Says He Is Ending Government Funding California’s High-Speed Rail Project

DON'T MISS

Bakersfield Tax Return Preparer Pleads Guilty in $25 Million Fraud Scheme

DON'T MISS

Congressional Hopeful Lorenzo Rios Says No to PBS Funding. Once Led Local Station

DON'T MISS

US Attorney Beckwith Dismissed by Trump Admin, Replaced With Sanchez

DON'T MISS

Trump Says He Would Love for Fed Chair Powell to Resign

DON'T MISS

Trump Says Coca-Cola Agreed to Use Real Cane Sugar in US

DON'T MISS

7.3 Magnitude Earthquake Strikes Off Alaska Coast. No Danger to California

DON'T MISS

US Renewable Power Transmission Project Under Fire From Farmers

DON'T MISS

Fresno Detectives Nab Murder Suspect With Help From Riverside Sheriff’s Deputies

DON'T MISS

Bains Is Challenging Valadao. An Early Look at Fundraising.

UP NEXT

Bakersfield Tax Return Preparer Pleads Guilty in $25 Million Fraud Scheme

UP NEXT

Congressional Hopeful Lorenzo Rios Says No to PBS Funding. Once Led Local Station

UP NEXT

US Attorney Beckwith Dismissed by Trump Admin, Replaced With Sanchez

UP NEXT

Trump Says He Would Love for Fed Chair Powell to Resign

UP NEXT

Trump Says Coca-Cola Agreed to Use Real Cane Sugar in US

UP NEXT

7.3 Magnitude Earthquake Strikes Off Alaska Coast. No Danger to California

UP NEXT

US Renewable Power Transmission Project Under Fire From Farmers

UP NEXT

Fresno Detectives Nab Murder Suspect With Help From Riverside Sheriff’s Deputies

UP NEXT

Bains Is Challenging Valadao. An Early Look at Fundraising.

UP NEXT

Trump, White House Race to Stem Epstein Conspiracy Fallout

US Attorney Beckwith Dismissed by Trump Admin, Replaced With Sanchez

4 hours ago

Trump Says He Would Love for Fed Chair Powell to Resign

4 hours ago

Trump Says Coca-Cola Agreed to Use Real Cane Sugar in US

5 hours ago

7.3 Magnitude Earthquake Strikes Off Alaska Coast. No Danger to California

5 hours ago

US Renewable Power Transmission Project Under Fire From Farmers

5 hours ago

Fresno Detectives Nab Murder Suspect With Help From Riverside Sheriff’s Deputies

7 hours ago

Bains Is Challenging Valadao. An Early Look at Fundraising.

8 hours ago

Trump, White House Race to Stem Epstein Conspiracy Fallout

8 hours ago

Wired Wednesday: Judge Gives Green Light to 4-Story NW Fresno Apt. Complex

9 hours ago

Federal Immigration Crackdown Threatens California’s Historic Housing Reforms

9 hours ago

Trump Says He Is Ending Government Funding California’s High-Speed Rail Project

WASHINGTON – President Donald Trump announced on Wednesday that he is ending government funding for California’s High-Speed Rail...

3 hours ago

A drone view of a California High-Speed Rail Bridge where it crosses through Fresno, California, U.S. June 8, 2025. (Reuters)
3 hours ago

Trump Says He Is Ending Government Funding California’s High-Speed Rail Project

4 hours ago

Bakersfield Tax Return Preparer Pleads Guilty in $25 Million Fraud Scheme

4 hours ago

Congressional Hopeful Lorenzo Rios Says No to PBS Funding. Once Led Local Station

4 hours ago

US Attorney Beckwith Dismissed by Trump Admin, Replaced With Sanchez

President Donald Trump looks on at the White House in Washington, D.C., U.S., July 16, 2025. (Reuters/Umit Bektas)
4 hours ago

Trump Says He Would Love for Fed Chair Powell to Resign

Coca-cola soda is shown on display during a preview of a new Walmart Super Center prior to its opening in Compton, California, U.S., January 10, 2017. (Reuters File)
5 hours ago

Trump Says Coca-Cola Agreed to Use Real Cane Sugar in US

5 hours ago

7.3 Magnitude Earthquake Strikes Off Alaska Coast. No Danger to California

Windmills line a hillside in Palm Springs, California, U.S., November 29, 2019. (Reuters File)
5 hours ago

US Renewable Power Transmission Project Under Fire From Farmers

Help continue the work that gets you the news that matters most.

Search

Send this to a friend