Please ensure Javascript is enabled for purposes of website accessibility
Hackers Exploit Chrome Extensions, Exposing Millions to 2FA Bypass Attacks
News
By News
Published 4 months ago on
December 31, 2024

Chrome extension vulnerabilities leave millions at risk of 2FA bypass attacks, with hackers targeting multiple companies. (Shutterstock)

Share

Getting your Trinity Audio player ready...

Google Chrome users face potential security risks as hackers target browser extensions to bypass two-factor authentication (2FA), as reported by Forbes.

The attacks, which began in mid-December, have compromised several companies’ Chrome extensions, potentially affecting millions of users.

Christmas Eve Attack

One notable incident involved Cyberhaven, a data attack detection company.

On Christmas Eve, a phishing attack compromised an employee’s credentials, allowing hackers to publish a malicious version of their Chrome extension. Cyberhaven CEO Howard Ting stated, “We want to share the full details of the incident and steps we’re taking to protect our customers and mitigate any damage.”

The attack bypassed 2FA by capturing session cookies, which authenticate user sessions. This method allows attackers to reuse the stolen cookies and access accounts without needing the 2FA code.

Google’s Recommendations to Mitigate Risks

To mitigate risks, Google recommends using passkeys and security keys. Vivek Ramachandran, founder of SquareX, suggests implementing server-side restrictions on risky OAuth scopes and using client-side Browser Detection-Response tools.

Google’s Chrome security team employs both automated and manual reviews to check extensions before publication on the Chrome Web Store. They also continuously monitor published extensions. Despite these efforts, some malicious extensions still slip through.

Users can protect themselves by:
1. Checking installed extensions at “chrome://extensions”
2. Running a Chrome Safety Check
3. Enabling enhanced protection mode in Safe Browsing

According to a Google spokesperson, “Google research has shown that security keys provide stronger protection against automated bots, bulk phishing attacks, and targeted attacks than SMS, app-based one-time passwords, and other forms of traditional two-factor authentication.”

Read more at Forbes

RELATED TOPICS:

DON'T MISS

What Are Fresno Real Estate Experts Predicting for 2025 and Beyond?

DON'T MISS

First California EV Mandates Hit Automakers This Year. Most Are Not Even Close

DON'T MISS

Yastrzemski and Chapman Homers Help Giants Rally Past the Brewers

DON'T MISS

Fresno City Council Finally Passes a Tough Smoke Shop Ordinance

DON'T MISS

Fresno Unified Trustee Wittrup Says District Had Stronger Candidates Than Misty Her

DON'T MISS

Trump Poised to Offer Saudi Arabia Over $100 Billion Arms Package, Sources Say

DON'T MISS

Lights, Camera, Board Vote: Fresno Unified’s Carefully Choreographed Production

DON'T MISS

US Farm Agency Withdraws Proposal Aimed at Lowering Salmonella Risks in Poultry

DON'T MISS

On Major Economic Decisions, Trump Blinks, and Then Blinks Again

DON'T MISS

Candi Is the Dandy to Add a Little Sweetness to Your Life

DON'T MISS

How Trump Tariffs Could Upend California Farms, Wine Businesses, and Ports

DON'T MISS

Tulare Man Sentenced to State Prison for DUI Crash That Injured Two Women

UP NEXT

Fresno City Council Finally Passes a Tough Smoke Shop Ordinance

UP NEXT

Fresno Unified Trustee Wittrup Says District Had Stronger Candidates Than Misty Her

UP NEXT

Trump Poised to Offer Saudi Arabia Over $100 Billion Arms Package, Sources Say

UP NEXT

Lights, Camera, Board Vote: Fresno Unified’s Carefully Choreographed Production

UP NEXT

US Farm Agency Withdraws Proposal Aimed at Lowering Salmonella Risks in Poultry

UP NEXT

On Major Economic Decisions, Trump Blinks, and Then Blinks Again

UP NEXT

Candi Is the Dandy to Add a Little Sweetness to Your Life

UP NEXT

How Trump Tariffs Could Upend California Farms, Wine Businesses, and Ports

UP NEXT

Tulare Man Sentenced to State Prison for DUI Crash That Injured Two Women

UP NEXT

Judge Partly Blocks Trump Order Seeking to Overhaul US Elections

Trump Poised to Offer Saudi Arabia Over $100 Billion Arms Package, Sources Say

7 hours ago

Lights, Camera, Board Vote: Fresno Unified’s Carefully Choreographed Production

8 hours ago

US Farm Agency Withdraws Proposal Aimed at Lowering Salmonella Risks in Poultry

8 hours ago

On Major Economic Decisions, Trump Blinks, and Then Blinks Again

8 hours ago

Candi Is the Dandy to Add a Little Sweetness to Your Life

9 hours ago

How Trump Tariffs Could Upend California Farms, Wine Businesses, and Ports

9 hours ago

Tulare Man Sentenced to State Prison for DUI Crash That Injured Two Women

10 hours ago

Judge Partly Blocks Trump Order Seeking to Overhaul US Elections

11 hours ago

Two From Search Group That Uncovered Mexico’s ‘Ranch of Horror’ Killed

11 hours ago

US Warns States They Could Lose Transportation Funding Over Immigration, DEI Policies

11 hours ago

Yastrzemski and Chapman Homers Help Giants Rally Past the Brewers

SAN FRANCISCO — Mike Yastrzemski and Matt Chapman homered as the San Francisco Giants rallied to beat the Milwaukee Brewers 6-5 on Thursday ...

5 hours ago

5 hours ago

Yastrzemski and Chapman Homers Help Giants Rally Past the Brewers

5 hours ago

Fresno City Council Finally Passes a Tough Smoke Shop Ordinance

7 hours ago

Fresno Unified Trustee Wittrup Says District Had Stronger Candidates Than Misty Her

President Donald Trump delivers remarks during an 'Unleashing American Energy' event at the Department of Energy in Washington, U.S., June 29, 2017. (REUTERS File)
7 hours ago

Trump Poised to Offer Saudi Arabia Over $100 Billion Arms Package, Sources Say

8 hours ago

Lights, Camera, Board Vote: Fresno Unified’s Carefully Choreographed Production

Chickens sit at a poultry farm. March 12, 2025. (REUTERS/Diego Vara/File Photo)
8 hours ago

US Farm Agency Withdraws Proposal Aimed at Lowering Salmonella Risks in Poultry

8 hours ago

On Major Economic Decisions, Trump Blinks, and Then Blinks Again

Candi, GV Wire's Adoptable Cat of the Week
9 hours ago

Candi Is the Dandy to Add a Little Sweetness to Your Life

Help continue the work that gets you the news that matters most.

Search

Send this to a friend