Please ensure Javascript is enabled for purposes of website accessibility
Hackers Exploit Chrome Extensions, Exposing Millions to 2FA Bypass Attacks
News
By News
Published 3 days ago on
December 31, 2024

Chrome extension vulnerabilities leave millions at risk of 2FA bypass attacks, with hackers targeting multiple companies. (Shutterstock)

Share

Getting your Trinity Audio player ready...

Google Chrome users face potential security risks as hackers target browser extensions to bypass two-factor authentication (2FA), as reported by Forbes.

The attacks, which began in mid-December, have compromised several companies’ Chrome extensions, potentially affecting millions of users.

Christmas Eve Attack

One notable incident involved Cyberhaven, a data attack detection company.

On Christmas Eve, a phishing attack compromised an employee’s credentials, allowing hackers to publish a malicious version of their Chrome extension. Cyberhaven CEO Howard Ting stated, “We want to share the full details of the incident and steps we’re taking to protect our customers and mitigate any damage.”

The attack bypassed 2FA by capturing session cookies, which authenticate user sessions. This method allows attackers to reuse the stolen cookies and access accounts without needing the 2FA code.

Google’s Recommendations to Mitigate Risks

To mitigate risks, Google recommends using passkeys and security keys. Vivek Ramachandran, founder of SquareX, suggests implementing server-side restrictions on risky OAuth scopes and using client-side Browser Detection-Response tools.

Google’s Chrome security team employs both automated and manual reviews to check extensions before publication on the Chrome Web Store. They also continuously monitor published extensions. Despite these efforts, some malicious extensions still slip through.

Users can protect themselves by:
1. Checking installed extensions at “chrome://extensions”
2. Running a Chrome Safety Check
3. Enabling enhanced protection mode in Safe Browsing

According to a Google spokesperson, “Google research has shown that security keys provide stronger protection against automated bots, bulk phishing attacks, and targeted attacks than SMS, app-based one-time passwords, and other forms of traditional two-factor authentication.”

Read more at Forbes

RELATED TOPICS:

DON'T MISS

John Thune Takes Charge in the Senate, Ushering in a New Leadership Era

DON'T MISS

10 Tips From Experts to Help You Change Your Relationship With Money in 2025

DON'T MISS

After Fierce Lobbying, Treasury Sets Rules for Billions in Hydrogen Subsidies

DON'T MISS

US Fines JetBlue $2 Million for ‘Chronic’ Flight Delays on Several East Coast Routes

DON'T MISS

Bourbon Street Returns to Life After Deadly Attack

DON'T MISS

California Begins 2025 With Solid Start to Winter Snowpack, but More Storms Are Needed

DON'T MISS

Biden Will Visit New Orleans on Monday in Wake of Deadly Bourbon Street Attack

DON'T MISS

Biden Blocks Nippon Steel’s Proposed Deal to Acquire US Steel

DON'T MISS

Israeli Strikes Kill at Least 30 in Gaza as Ceasefire Talks Set to Resume in Qatar

DON'T MISS

Surgeon General Calls for New Label on Drinks to Warn Americans of Alcohol’s Cancer Risk

UP NEXT

10 Tips From Experts to Help You Change Your Relationship With Money in 2025

UP NEXT

After Fierce Lobbying, Treasury Sets Rules for Billions in Hydrogen Subsidies

UP NEXT

US Fines JetBlue $2 Million for ‘Chronic’ Flight Delays on Several East Coast Routes

UP NEXT

Bourbon Street Returns to Life After Deadly Attack

UP NEXT

California Begins 2025 With Solid Start to Winter Snowpack, but More Storms Are Needed

UP NEXT

Biden Will Visit New Orleans on Monday in Wake of Deadly Bourbon Street Attack

UP NEXT

Biden Blocks Nippon Steel’s Proposed Deal to Acquire US Steel

UP NEXT

Israeli Strikes Kill at Least 30 in Gaza as Ceasefire Talks Set to Resume in Qatar

UP NEXT

Surgeon General Calls for New Label on Drinks to Warn Americans of Alcohol’s Cancer Risk

UP NEXT

LeBron James, Max Christie Carry Lakers Past Blazers for Their 6th Win in 8 Games

US Fines JetBlue $2 Million for ‘Chronic’ Flight Delays on Several East Coast Routes

9 minutes ago

Bourbon Street Returns to Life After Deadly Attack

12 minutes ago

California Begins 2025 With Solid Start to Winter Snowpack, but More Storms Are Needed

13 minutes ago

Biden Will Visit New Orleans on Monday in Wake of Deadly Bourbon Street Attack

23 minutes ago

Biden Blocks Nippon Steel’s Proposed Deal to Acquire US Steel

25 minutes ago

Israeli Strikes Kill at Least 30 in Gaza as Ceasefire Talks Set to Resume in Qatar

33 minutes ago

Surgeon General Calls for New Label on Drinks to Warn Americans of Alcohol’s Cancer Risk

37 minutes ago

LeBron James, Max Christie Carry Lakers Past Blazers for Their 6th Win in 8 Games

43 minutes ago

Fresno Police Arrest Nine at DUI Checkpoint in Year-End Operation

47 minutes ago

Stephen Curry Scores 30 Points, Makes All 8 3-Point Attempts in Warriors’ Win Over 76ers

54 minutes ago

John Thune Takes Charge in the Senate, Ushering in a New Leadership Era

WASHINGTON — John Thune won election to the Senate in 2004 by conquering Sen. Tom Daschle, the powerful Democratic majority leader, only to ...

18 seconds ago

Sen. John Thune (R-S.D.) during a weekly news conference on Capitol Hill in Washington, April 9, 2024. One of Thune’s first challenges as majority leader will be to shepherd multiple Trump nominees to confirmation in the closely divided Senate. (Kenny Holston/The New York Times)
18 seconds ago

John Thune Takes Charge in the Senate, Ushering in a New Leadership Era

1 minute ago

10 Tips From Experts to Help You Change Your Relationship With Money in 2025

Workers move an electrolyzer, which generates hydrogen from water using electricity, at a storage facility in Delta, Utah on Oct. 5, 2023. The Biden administration on Jan. 3, 2025 made final its long-awaited plan to offer billions of dollars in tax credits to companies that make hydrogen, in the hopes of building up a new industry that might help fight climate change. (Nina Riggio/The New York Times)
7 minutes ago

After Fierce Lobbying, Treasury Sets Rules for Billions in Hydrogen Subsidies

9 minutes ago

US Fines JetBlue $2 Million for ‘Chronic’ Flight Delays on Several East Coast Routes

A woman on Bienville Street looks into Bourbon Street next to a barricade with a lifting face, designed to block vehicle traffic, in the French Quarter of New Orleans, on Wednesday, Jan. 1, 2025. A man “trying to run over as many people as he possibly could” rammed a pickup into celebrating crowds on Bourbon Street in the early hours of New Year’s Day, killing at least 10 people and injuring about 35 others before dying in a shootout with police officers, officials said. (Edmund D. Fountain/The New York Times)
12 minutes ago

Bourbon Street Returns to Life After Deadly Attack

13 minutes ago

California Begins 2025 With Solid Start to Winter Snowpack, but More Storms Are Needed

23 minutes ago

Biden Will Visit New Orleans on Monday in Wake of Deadly Bourbon Street Attack

25 minutes ago

Biden Blocks Nippon Steel’s Proposed Deal to Acquire US Steel

Help continue the work that gets you the news that matters most.

Search

Send this to a friend