Please ensure Javascript is enabled for purposes of website accessibility
Hackers Exploit Chrome Extensions, Exposing Millions to 2FA Bypass Attacks
News
By News
Published 6 months ago on
December 31, 2024

Chrome extension vulnerabilities leave millions at risk of 2FA bypass attacks, with hackers targeting multiple companies. (Shutterstock)

Share

Getting your Trinity Audio player ready...

Google Chrome users face potential security risks as hackers target browser extensions to bypass two-factor authentication (2FA), as reported by Forbes.

The attacks, which began in mid-December, have compromised several companies’ Chrome extensions, potentially affecting millions of users.

Christmas Eve Attack

One notable incident involved Cyberhaven, a data attack detection company.

On Christmas Eve, a phishing attack compromised an employee’s credentials, allowing hackers to publish a malicious version of their Chrome extension. Cyberhaven CEO Howard Ting stated, “We want to share the full details of the incident and steps we’re taking to protect our customers and mitigate any damage.”

The attack bypassed 2FA by capturing session cookies, which authenticate user sessions. This method allows attackers to reuse the stolen cookies and access accounts without needing the 2FA code.

Google’s Recommendations to Mitigate Risks

To mitigate risks, Google recommends using passkeys and security keys. Vivek Ramachandran, founder of SquareX, suggests implementing server-side restrictions on risky OAuth scopes and using client-side Browser Detection-Response tools.

Google’s Chrome security team employs both automated and manual reviews to check extensions before publication on the Chrome Web Store. They also continuously monitor published extensions. Despite these efforts, some malicious extensions still slip through.

Users can protect themselves by:
1. Checking installed extensions at “chrome://extensions”
2. Running a Chrome Safety Check
3. Enabling enhanced protection mode in Safe Browsing

According to a Google spokesperson, “Google research has shown that security keys provide stronger protection against automated bots, bulk phishing attacks, and targeted attacks than SMS, app-based one-time passwords, and other forms of traditional two-factor authentication.”

Read more at Forbes

RELATED TOPICS:

DON'T MISS

What Are Fresno Real Estate Experts Predicting for 2025 and Beyond?

DON'T MISS

First California EV Mandates Hit Automakers This Year. Most Are Not Even Close

DON'T MISS

4 Million Acres of California Forests Could Lose Protection. What Trump’s ‘Roadless Rule’ Repeal Could Do

DON'T MISS

Israeli Settlers Raid West Bank Town, Troops Kill 3 Palestinians

DON'T MISS

West Nile Virus Detected in Mosquitoes in Fresno County

DON'T MISS

Trump Says Netanyahu’s Trial Should Be Canceled

DON'T MISS

St. Agnes’ New Chief Medical Officer Is a Kidney Care Expert

DON'T MISS

US Military to Create Two New Border Zones, Officials Say

DON'T MISS

Trump Signals US May Ease Iran Oil Sanction Enforcement to Help Rebuild Country

DON'T MISS

CIA Says Intelligence Indicates Iran’s Nuclear Program Severely Damaged

DON'T MISS

Upscale Woodward Park Area Apartments Sell for $19 Million

DON'T MISS

Wired Wednesday: Learn the Latest on the Caleb Quick Murder Hearings

UP NEXT

Israeli Settlers Raid West Bank Town, Troops Kill 3 Palestinians

UP NEXT

West Nile Virus Detected in Mosquitoes in Fresno County

UP NEXT

Trump Says Netanyahu’s Trial Should Be Canceled

UP NEXT

St. Agnes’ New Chief Medical Officer Is a Kidney Care Expert

UP NEXT

US Military to Create Two New Border Zones, Officials Say

UP NEXT

Trump Signals US May Ease Iran Oil Sanction Enforcement to Help Rebuild Country

UP NEXT

CIA Says Intelligence Indicates Iran’s Nuclear Program Severely Damaged

UP NEXT

Upscale Woodward Park Area Apartments Sell for $19 Million

UP NEXT

Wired Wednesday: Learn the Latest on the Caleb Quick Murder Hearings

UP NEXT

Trump Administration Orders CA to Strip Trans Athlete of Medals

Cargo Ship That Caught Fire Carrying Electric Vehicles Sinks in the Pacific

39 minutes ago

How the United States Helped Create Iran’s Nuclear Program

42 minutes ago

Driver Arrested for DUI After Rolling Car on Highway 168

49 minutes ago

US Senate Republicans Race to Resolve Tax, Health Issues in Trump’s Tax Bill

57 minutes ago

Israel Halts Aid Into Gaza, Official Says, Clans Deny Hamas Is Stealing It

60 minutes ago

US Supreme Court Backs South Carolina Effort to Defund Planned Parenthood

1 hour ago

4 Million Acres of California Forests Could Lose Protection. What Trump’s ‘Roadless Rule’ Repeal Could Do

16 hours ago

Israeli Settlers Raid West Bank Town, Troops Kill 3 Palestinians

17 hours ago

West Nile Virus Detected in Mosquitoes in Fresno County

17 hours ago

Trump Says Netanyahu’s Trial Should Be Canceled

17 hours ago

Fresno, Kings Counties See Large Police Sweep. Officials Say ICE Not Involved.

A large multi-agency law enforcement operation took place Thursday morning in Fresno and Kings counties, as officers served search warrants ...

46 seconds ago

46 seconds ago

Fresno, Kings Counties See Large Police Sweep. Officials Say ICE Not Involved.

A view shows the New York Stock Exchange (NYSE) Wall Street entrance in New York City, U.S., April 7, 2025. (Reuters File)
25 minutes ago

S&P 500, Nasdaq Near Record Highs as Rate-Cut Bets Creep Up

Bobby Sherman, a 1960s teen idol known for hits like “Little Woman” and his role on “Here Come the Brides,” has died at 81. (Shutterstock)
32 minutes ago

Bobby Sherman, Easygoing Teen Idol of the 1960s and ’70s, Dies at 81

A photo provided by the U.S. Coast Guard, shows smoke rising from cargo vessel Morning Midas approximately 300 miles south of Adak, Alaska, June 3, 2025. Three weeks after a fire broke out on the ship off the coast of Alaska, the Morning Midas sank, along with thousands of cars on board. (U.S. Coast Guard via The New York Times)
39 minutes ago

Cargo Ship That Caught Fire Carrying Electric Vehicles Sinks in the Pacific

42 minutes ago

How the United States Helped Create Iran’s Nuclear Program

A driver was arrested for DUI after rolling a car on Highway 168 near the Four Lanes following a day of drinking, CHP said. (CHP)
49 minutes ago

Driver Arrested for DUI After Rolling Car on Highway 168

Visitors to the U.S. Capitol rest in the shade on Capitol Hill in Washington, D.C., U.S., June 25, 2025. (Reuters/Nathan Howard)
57 minutes ago

US Senate Republicans Race to Resolve Tax, Health Issues in Trump’s Tax Bill

Mourners pray as they attend the funeral of Palestinians killed, in what the Gaza Health Ministry said, were overnight Israeli airstrikes on tents sheltering displaced people, at Nasser hospital, in Khan Younis, southern Gaza Strip, June 26, 2025. (Reuters/Hatem Khaled)
1 hour ago

Israel Halts Aid Into Gaza, Official Says, Clans Deny Hamas Is Stealing It

Help continue the work that gets you the news that matters most.

Search

Send this to a friend