Please ensure Javascript is enabled for purposes of website accessibility
Hackers Exploit Chrome Extensions, Exposing Millions to 2FA Bypass Attacks
News
By News
Published 5 days ago on
December 31, 2024

Chrome extension vulnerabilities leave millions at risk of 2FA bypass attacks, with hackers targeting multiple companies. (Shutterstock)

Share

Getting your Trinity Audio player ready...

Google Chrome users face potential security risks as hackers target browser extensions to bypass two-factor authentication (2FA), as reported by Forbes.

The attacks, which began in mid-December, have compromised several companies’ Chrome extensions, potentially affecting millions of users.

Christmas Eve Attack

One notable incident involved Cyberhaven, a data attack detection company.

On Christmas Eve, a phishing attack compromised an employee’s credentials, allowing hackers to publish a malicious version of their Chrome extension. Cyberhaven CEO Howard Ting stated, “We want to share the full details of the incident and steps we’re taking to protect our customers and mitigate any damage.”

The attack bypassed 2FA by capturing session cookies, which authenticate user sessions. This method allows attackers to reuse the stolen cookies and access accounts without needing the 2FA code.

Google’s Recommendations to Mitigate Risks

To mitigate risks, Google recommends using passkeys and security keys. Vivek Ramachandran, founder of SquareX, suggests implementing server-side restrictions on risky OAuth scopes and using client-side Browser Detection-Response tools.

Google’s Chrome security team employs both automated and manual reviews to check extensions before publication on the Chrome Web Store. They also continuously monitor published extensions. Despite these efforts, some malicious extensions still slip through.

Users can protect themselves by:
1. Checking installed extensions at “chrome://extensions”
2. Running a Chrome Safety Check
3. Enabling enhanced protection mode in Safe Browsing

According to a Google spokesperson, “Google research has shown that security keys provide stronger protection against automated bots, bulk phishing attacks, and targeted attacks than SMS, app-based one-time passwords, and other forms of traditional two-factor authentication.”

Read more at Forbes

RELATED TOPICS:

DON'T MISS

With a Nod to Her Mentor Shirley Chisholm, Rep. Barbara Lee Exits Congress as a Renegade Herself

DON'T MISS

EV Demand Leads Automakers to Strong 2024 Finish

DON'T MISS

Why 2025 Will Be a Pivotal Year for Mayor Karen Bass and LA

DON'T MISS

From Georgia to Washington, Memorials Trace Jimmy Carter’s Life

DON'T MISS

Is Your Car Spying on You? What It Means That Tesla Shared Data in Las Vegas Explosion

DON'T MISS

Can California Keep ICE Away from Schools? Lawmakers Want to Try as Crackdowns Loom

DON'T MISS

Elon Musk Announces Algorithm Change to Reduce Negativity on X

DON'T MISS

Indie Filmmaker Jeff Baena, Aubrey Plaza’s Husband, Found Dead at Los Angeles Residence

DON'T MISS

Israeli Airstrikes in Gaza Kill at Least 21, Hospital Workers Say

DON'T MISS

Newsom Executive Order Targets Ultra-Processed Foods, Synthetic Dyes

UP NEXT

EV Demand Leads Automakers to Strong 2024 Finish

UP NEXT

Why 2025 Will Be a Pivotal Year for Mayor Karen Bass and LA

UP NEXT

From Georgia to Washington, Memorials Trace Jimmy Carter’s Life

UP NEXT

Is Your Car Spying on You? What It Means That Tesla Shared Data in Las Vegas Explosion

UP NEXT

Can California Keep ICE Away from Schools? Lawmakers Want to Try as Crackdowns Loom

UP NEXT

Elon Musk Announces Algorithm Change to Reduce Negativity on X

UP NEXT

Indie Filmmaker Jeff Baena, Aubrey Plaza’s Husband, Found Dead at Los Angeles Residence

UP NEXT

Israeli Airstrikes in Gaza Kill at Least 21, Hospital Workers Say

UP NEXT

Newsom Executive Order Targets Ultra-Processed Foods, Synthetic Dyes

UP NEXT

Net Neutrality Rules Struck Down by Appeals Court

From Georgia to Washington, Memorials Trace Jimmy Carter’s Life

17 hours ago

Is Your Car Spying on You? What It Means That Tesla Shared Data in Las Vegas Explosion

17 hours ago

Can California Keep ICE Away from Schools? Lawmakers Want to Try as Crackdowns Loom

18 hours ago

Elon Musk Announces Algorithm Change to Reduce Negativity on X

18 hours ago

Indie Filmmaker Jeff Baena, Aubrey Plaza’s Husband, Found Dead at Los Angeles Residence

21 hours ago

Israeli Airstrikes in Gaza Kill at Least 21, Hospital Workers Say

21 hours ago

Newsom Executive Order Targets Ultra-Processed Foods, Synthetic Dyes

24 hours ago

Net Neutrality Rules Struck Down by Appeals Court

24 hours ago

Taiwan Says China Is Redoubling Efforts to Undermine Democracy With Disinformation

1 day ago

LeBron James Breaks Michael Jordan’s Record for 30-Point Games With His 563rd

1 day ago

With a Nod to Her Mentor Shirley Chisholm, Rep. Barbara Lee Exits Congress as a Renegade Herself

WASHINGTON — Rep. Barbara Lee has always stood apart, a matter-of-fact renegade with a long list of firsts. In high school, she was the firs...

4 hours ago

4 hours ago

With a Nod to Her Mentor Shirley Chisholm, Rep. Barbara Lee Exits Congress as a Renegade Herself

4 hours ago

EV Demand Leads Automakers to Strong 2024 Finish

5 hours ago

Why 2025 Will Be a Pivotal Year for Mayor Karen Bass and LA

17 hours ago

From Georgia to Washington, Memorials Trace Jimmy Carter’s Life

17 hours ago

Is Your Car Spying on You? What It Means That Tesla Shared Data in Las Vegas Explosion

18 hours ago

Can California Keep ICE Away from Schools? Lawmakers Want to Try as Crackdowns Loom

Elon Musk and X
18 hours ago

Elon Musk Announces Algorithm Change to Reduce Negativity on X

21 hours ago

Indie Filmmaker Jeff Baena, Aubrey Plaza’s Husband, Found Dead at Los Angeles Residence

Help continue the work that gets you the news that matters most.

Search

Send this to a friend