Please ensure Javascript is enabled for purposes of website accessibility
Hackers Exploit Chrome Extensions, Exposing Millions to 2FA Bypass Attacks
News
By News
Published 3 weeks ago on
December 31, 2024

Chrome extension vulnerabilities leave millions at risk of 2FA bypass attacks, with hackers targeting multiple companies. (Shutterstock)

Share

Getting your Trinity Audio player ready...

Google Chrome users face potential security risks as hackers target browser extensions to bypass two-factor authentication (2FA), as reported by Forbes.

The attacks, which began in mid-December, have compromised several companies’ Chrome extensions, potentially affecting millions of users.

Christmas Eve Attack

One notable incident involved Cyberhaven, a data attack detection company.

On Christmas Eve, a phishing attack compromised an employee’s credentials, allowing hackers to publish a malicious version of their Chrome extension. Cyberhaven CEO Howard Ting stated, “We want to share the full details of the incident and steps we’re taking to protect our customers and mitigate any damage.”

The attack bypassed 2FA by capturing session cookies, which authenticate user sessions. This method allows attackers to reuse the stolen cookies and access accounts without needing the 2FA code.

Google’s Recommendations to Mitigate Risks

To mitigate risks, Google recommends using passkeys and security keys. Vivek Ramachandran, founder of SquareX, suggests implementing server-side restrictions on risky OAuth scopes and using client-side Browser Detection-Response tools.

Google’s Chrome security team employs both automated and manual reviews to check extensions before publication on the Chrome Web Store. They also continuously monitor published extensions. Despite these efforts, some malicious extensions still slip through.

Users can protect themselves by:
1. Checking installed extensions at “chrome://extensions”
2. Running a Chrome Safety Check
3. Enabling enhanced protection mode in Safe Browsing

According to a Google spokesperson, “Google research has shown that security keys provide stronger protection against automated bots, bulk phishing attacks, and targeted attacks than SMS, app-based one-time passwords, and other forms of traditional two-factor authentication.”

Read more at Forbes

RELATED TOPICS:

DON'T MISS

Immigrant Parents Weigh the Risk of Sending Children to School After Trump Policy Change

DON'T MISS

Fire Risk, Strong Winds Continue in Southern California With Potential Rain on the Horizon

DON'T MISS

Danish Politician Tells Trump to ‘F— Off’ Regarding Greenland

DON'T MISS

LA Fires Add Tricky New Wrinkle to Trump-Newsom Feud

DON'T MISS

Taylor Swift and Morgan Wallen Lead the 2025 iHeartRadio Music Award Nominations

DON'T MISS

Pentagon to Send up to 1,500 Active Duty Troops to Help Secure US-Mexico Border

DON'T MISS

Border Security Is Popular – but That May Be the Limit of US Immigration Consensus: Poll

DON'T MISS

Trump Administration Freezes Many Health Agency Reports and Posts

DON'T MISS

Trump Administration Shuts Down White House Spanish-Language Page and Social Media

DON'T MISS

Valley Crime Stoppers’ Most Wanted Person of the Day: Nicholas Ryan Hernandez

UP NEXT

Fire Risk, Strong Winds Continue in Southern California With Potential Rain on the Horizon

UP NEXT

Danish Politician Tells Trump to ‘F— Off’ Regarding Greenland

UP NEXT

LA Fires Add Tricky New Wrinkle to Trump-Newsom Feud

UP NEXT

Taylor Swift and Morgan Wallen Lead the 2025 iHeartRadio Music Award Nominations

UP NEXT

Pentagon to Send up to 1,500 Active Duty Troops to Help Secure US-Mexico Border

UP NEXT

Border Security Is Popular – but That May Be the Limit of US Immigration Consensus: Poll

UP NEXT

Trump Administration Freezes Many Health Agency Reports and Posts

UP NEXT

Trump Administration Shuts Down White House Spanish-Language Page and Social Media

UP NEXT

Valley Crime Stoppers’ Most Wanted Person of the Day: Nicholas Ryan Hernandez

UP NEXT

Trump Administration Cancels Travel for Refugees Already Cleared to Resettle in the US

LA Fires Add Tricky New Wrinkle to Trump-Newsom Feud

44 minutes ago

Taylor Swift and Morgan Wallen Lead the 2025 iHeartRadio Music Award Nominations

50 minutes ago

Pentagon to Send up to 1,500 Active Duty Troops to Help Secure US-Mexico Border

2 hours ago

Border Security Is Popular – but That May Be the Limit of US Immigration Consensus: Poll

2 hours ago

Trump Administration Freezes Many Health Agency Reports and Posts

2 hours ago

Trump Administration Shuts Down White House Spanish-Language Page and Social Media

2 hours ago

Valley Crime Stoppers’ Most Wanted Person of the Day: Nicholas Ryan Hernandez

2 hours ago

Trump Administration Cancels Travel for Refugees Already Cleared to Resettle in the US

2 hours ago

Trump Orders Putting ‘People Over Fish.’ Will He Succeed?

2 hours ago

Afghans Who Fled Taliban Rule Urge Trump to Lift Refugee Program Suspension

3 hours ago

Immigrant Parents Weigh the Risk of Sending Children to School After Trump Policy Change

SAN FRANCISCO — As President Donald Trump cracks down on immigrants in the U.S. illegally, some families are wondering if it is safe to send...

18 minutes ago

A student arrives for school Tuesday, Jan. 21, 2025, in the East Boston neighborhood of Boston. (AP Photo/Michael Dwyer)
18 minutes ago

Immigrant Parents Weigh the Risk of Sending Children to School After Trump Policy Change

A firefighter battles the Lilac Fire near the Bonsall community of San Diego County, Calif., on Tuesday, Jan. 21, 2025. (AP Photo/Noah Berger)
25 minutes ago

Fire Risk, Strong Winds Continue in Southern California With Potential Rain on the Horizon

Danish politician, Anders Vistisen, tells President Donald Trump to 'f--- off' when responding to Trump's desire to purchase Greenland from Denmark. (GV Wire Composite/Anthony W. Haddad)
36 minutes ago

Danish Politician Tells Trump to ‘F— Off’ Regarding Greenland

Newsom Trump Survey Paradise Fire Aftermath
44 minutes ago

LA Fires Add Tricky New Wrinkle to Trump-Newsom Feud

Taylor Swift appears at the MTV Video Music Awards in Elmont, N.Y., on Sept. 11, 2024, left, and Morgan Wallen appears at the 57th Annual CMA Awards in Nashville, Tenn., on Nov. 8, 2023. (Photos by Evan Agostini/Invision/AP)
50 minutes ago

Taylor Swift and Morgan Wallen Lead the 2025 iHeartRadio Music Award Nominations

Dogs are near a border wall separating Mexico from the United States Wednesday, Jan. 22, 2025, in San Diego. (AP/Gregory Bull)
2 hours ago

Pentagon to Send up to 1,500 Active Duty Troops to Help Secure US-Mexico Border

A national guardsman patrols along a stretch of boarder wall, Tuesday, Jan. 21, 2025, in Brownsville, Texas. (AP/Eric Gay)
2 hours ago

Border Security Is Popular – but That May Be the Limit of US Immigration Consensus: Poll

President Donald Trump talks about drug prices during a visit to the Department of Health and Human Services in Washington, Oct. 25, 2018. HHS Secretary Alex Azar listens at right. (AP File)
2 hours ago

Trump Administration Freezes Many Health Agency Reports and Posts

Help continue the work that gets you the news that matters most.

Search

Send this to a friend