Please ensure Javascript is enabled for purposes of website accessibility
Hackers Exploit Chrome Extensions, Exposing Millions to 2FA Bypass Attacks
News
By News
Published 1 month ago on
December 31, 2024

Chrome extension vulnerabilities leave millions at risk of 2FA bypass attacks, with hackers targeting multiple companies. (Shutterstock)

Share

Getting your Trinity Audio player ready...

Google Chrome users face potential security risks as hackers target browser extensions to bypass two-factor authentication (2FA), as reported by Forbes.

The attacks, which began in mid-December, have compromised several companies’ Chrome extensions, potentially affecting millions of users.

Christmas Eve Attack

One notable incident involved Cyberhaven, a data attack detection company.

On Christmas Eve, a phishing attack compromised an employee’s credentials, allowing hackers to publish a malicious version of their Chrome extension. Cyberhaven CEO Howard Ting stated, “We want to share the full details of the incident and steps we’re taking to protect our customers and mitigate any damage.”

The attack bypassed 2FA by capturing session cookies, which authenticate user sessions. This method allows attackers to reuse the stolen cookies and access accounts without needing the 2FA code.

Google’s Recommendations to Mitigate Risks

To mitigate risks, Google recommends using passkeys and security keys. Vivek Ramachandran, founder of SquareX, suggests implementing server-side restrictions on risky OAuth scopes and using client-side Browser Detection-Response tools.

Google’s Chrome security team employs both automated and manual reviews to check extensions before publication on the Chrome Web Store. They also continuously monitor published extensions. Despite these efforts, some malicious extensions still slip through.

Users can protect themselves by:
1. Checking installed extensions at “chrome://extensions”
2. Running a Chrome Safety Check
3. Enabling enhanced protection mode in Safe Browsing

According to a Google spokesperson, “Google research has shown that security keys provide stronger protection against automated bots, bulk phishing attacks, and targeted attacks than SMS, app-based one-time passwords, and other forms of traditional two-factor authentication.”

Read more at Forbes

RELATED TOPICS:

DON'T MISS

Judge Says Fresno Can Change Street Names: Cesar Chavez Blvd Lawsuit Tossed

DON'T MISS

The Aga Khan, Spiritual Leader of Ismaili Muslims and a Philanthropist, Dies at 88

DON'T MISS

Trump Wants US to Take Ownership of Gaza and Redevelop It After Palestinians Are Resettled

DON'T MISS

Fresno High-Speed Chase Ends in Arrests After Crash, Standoff

DON'T MISS

NFL Commish Calls Chiefs Conspiracy Theory ‘Ridiculous’ but Terrell Owens Floats One

DON'T MISS

Where Will Californians Rally During Nationwide Protest Against Trump Administration?

DON'T MISS

Estee Lauder to Cut up to 7,000 Jobs as Sales Slide

DON'T MISS

Visalia Police Arrest Three, Seize Ghost Gun and Drugs

DON'T MISS

Mexico Deploys 10,000 National Guard Members to US Border: What to Know

DON'T MISS

Trump Says the ‘Gaza Thing Has Never Worked’

UP NEXT

The Aga Khan, Spiritual Leader of Ismaili Muslims and a Philanthropist, Dies at 88

UP NEXT

Trump Wants US to Take Ownership of Gaza and Redevelop It After Palestinians Are Resettled

UP NEXT

Fresno High-Speed Chase Ends in Arrests After Crash, Standoff

UP NEXT

NFL Commish Calls Chiefs Conspiracy Theory ‘Ridiculous’ but Terrell Owens Floats One

UP NEXT

Where Will Californians Rally During Nationwide Protest Against Trump Administration?

UP NEXT

Estee Lauder to Cut up to 7,000 Jobs as Sales Slide

UP NEXT

Visalia Police Arrest Three, Seize Ghost Gun and Drugs

UP NEXT

Mexico Deploys 10,000 National Guard Members to US Border: What to Know

UP NEXT

Trump Says the ‘Gaza Thing Has Never Worked’

UP NEXT

First Military Flight Departs to Send Migrants to Guantanamo Bay

Fresno High-Speed Chase Ends in Arrests After Crash, Standoff

2 hours ago

NFL Commish Calls Chiefs Conspiracy Theory ‘Ridiculous’ but Terrell Owens Floats One

2 hours ago

Where Will Californians Rally During Nationwide Protest Against Trump Administration?

2 hours ago

Estee Lauder to Cut up to 7,000 Jobs as Sales Slide

3 hours ago

Visalia Police Arrest Three, Seize Ghost Gun and Drugs

3 hours ago

Mexico Deploys 10,000 National Guard Members to US Border: What to Know

3 hours ago

Trump Says the ‘Gaza Thing Has Never Worked’

4 hours ago

First Military Flight Departs to Send Migrants to Guantanamo Bay

4 hours ago

A Tale of Two Local Districts: Implementing the CA Classroom Cell Phone Ban

5 hours ago

Hawaii Volcano Produces Tall Lava Fountaining in Latest Episode of Kilauea Eruption

5 hours ago

Judge Says Fresno Can Change Street Names: Cesar Chavez Blvd Lawsuit Tossed

Shortly after renaming eight miles of streets in south Fresno to honor labor organizer Cesar Chavez, a group of business owners and resident...

29 minutes ago

29 minutes ago

Judge Says Fresno Can Change Street Names: Cesar Chavez Blvd Lawsuit Tossed

The Aga Khan, spiritual head of Ismaili Muslims, listens to a speech during the inauguration of the restored 16th century Humayun's Tomb in New Delhi, India, Sept. 18, 2013. (AP File)
1 hour ago

The Aga Khan, Spiritual Leader of Ismaili Muslims and a Philanthropist, Dies at 88

2 hours ago

Trump Wants US to Take Ownership of Gaza and Redevelop It After Palestinians Are Resettled

A hit-and-run response in Fresno led to a high-speed chase, crash, and standoff, ending in two arrests after police intervention. (CHP)
2 hours ago

Fresno High-Speed Chase Ends in Arrests After Crash, Standoff

2 hours ago

NFL Commish Calls Chiefs Conspiracy Theory ‘Ridiculous’ but Terrell Owens Floats One

The 50501 Movement, a grassroots protest effort organizing demonstrations in all 50 states on February 5 to oppose fascism, emphasizes peaceful action and local participation, with planned protests at key sites, including California’s state Capitol. (GV Wire Composite)
2 hours ago

Where Will Californians Rally During Nationwide Protest Against Trump Administration?

3 hours ago

Estee Lauder to Cut up to 7,000 Jobs as Sales Slide

Three people were arrested on Tuesday, Feb. 4, 2025, in Visalia after police found a ghost gun, high-capacity magazines, and drugs during a search warrant. (Visalia PD)
3 hours ago

Visalia Police Arrest Three, Seize Ghost Gun and Drugs

Help continue the work that gets you the news that matters most.

Search

Send this to a friend