Please ensure Javascript is enabled for purposes of website accessibility
Hackers Exploit Chrome Extensions, Exposing Millions to 2FA Bypass Attacks
News
By News
Published 4 months ago on
December 31, 2024

Chrome extension vulnerabilities leave millions at risk of 2FA bypass attacks, with hackers targeting multiple companies. (Shutterstock)

Share

Getting your Trinity Audio player ready...

Google Chrome users face potential security risks as hackers target browser extensions to bypass two-factor authentication (2FA), as reported by Forbes.

The attacks, which began in mid-December, have compromised several companies’ Chrome extensions, potentially affecting millions of users.

Christmas Eve Attack

One notable incident involved Cyberhaven, a data attack detection company.

On Christmas Eve, a phishing attack compromised an employee’s credentials, allowing hackers to publish a malicious version of their Chrome extension. Cyberhaven CEO Howard Ting stated, “We want to share the full details of the incident and steps we’re taking to protect our customers and mitigate any damage.”

The attack bypassed 2FA by capturing session cookies, which authenticate user sessions. This method allows attackers to reuse the stolen cookies and access accounts without needing the 2FA code.

Google’s Recommendations to Mitigate Risks

To mitigate risks, Google recommends using passkeys and security keys. Vivek Ramachandran, founder of SquareX, suggests implementing server-side restrictions on risky OAuth scopes and using client-side Browser Detection-Response tools.

Google’s Chrome security team employs both automated and manual reviews to check extensions before publication on the Chrome Web Store. They also continuously monitor published extensions. Despite these efforts, some malicious extensions still slip through.

Users can protect themselves by:
1. Checking installed extensions at “chrome://extensions”
2. Running a Chrome Safety Check
3. Enabling enhanced protection mode in Safe Browsing

According to a Google spokesperson, “Google research has shown that security keys provide stronger protection against automated bots, bulk phishing attacks, and targeted attacks than SMS, app-based one-time passwords, and other forms of traditional two-factor authentication.”

Read more at Forbes

RELATED TOPICS:

DON'T MISS

What Are Fresno Real Estate Experts Predicting for 2025 and Beyond?

DON'T MISS

First California EV Mandates Hit Automakers This Year. Most Are Not Even Close

DON'T MISS

49ers Draft Georgia Edge Rusher Mykel Williams With the No. 11 Pick in the NFL Draft

DON'T MISS

Trump’s Immigration Approval Ratings Decline as Enforcement Tactics Lose Support

DON'T MISS

Fresno Man Tased, Arrested After Suspected Reckless DUI in Kerman

DON'T MISS

Madera Vehicle Burglary Leads to Arrests, Gang Charges for Juveniles

DON'T MISS

Why Texas Is Ahead of California on Bilingual Education

DON'T MISS

US Universities Help Foreign Students Weather Trump Deportations

DON'T MISS

Alphabet Says Waymo May Offer Robotaxis for Personal Ownership in Future

DON'T MISS

US Pharma Tariffs Would Raise US Drug Costs by $51 Billion Annually, Report Finds

DON'T MISS

Beware of Scammers Saying You Won the Publishers Clearing House Drawing

DON'T MISS

Abundance Meets Resistance: Are CA Dems Finally Ready to Go All In on Building Housing?

UP NEXT

Trump’s Immigration Approval Ratings Decline as Enforcement Tactics Lose Support

UP NEXT

Fresno Man Tased, Arrested After Suspected Reckless DUI in Kerman

UP NEXT

Madera Vehicle Burglary Leads to Arrests, Gang Charges for Juveniles

UP NEXT

Why Texas Is Ahead of California on Bilingual Education

UP NEXT

US Universities Help Foreign Students Weather Trump Deportations

UP NEXT

Alphabet Says Waymo May Offer Robotaxis for Personal Ownership in Future

UP NEXT

US Pharma Tariffs Would Raise US Drug Costs by $51 Billion Annually, Report Finds

UP NEXT

Beware of Scammers Saying You Won the Publishers Clearing House Drawing

UP NEXT

Abundance Meets Resistance: Are CA Dems Finally Ready to Go All In on Building Housing?

UP NEXT

Less Than Half of Californians Think K-12 Schools Are on the Right Track: Poll

Madera Vehicle Burglary Leads to Arrests, Gang Charges for Juveniles

34 minutes ago

Why Texas Is Ahead of California on Bilingual Education

46 minutes ago

US Universities Help Foreign Students Weather Trump Deportations

1 hour ago

Alphabet Says Waymo May Offer Robotaxis for Personal Ownership in Future

1 hour ago

US Pharma Tariffs Would Raise US Drug Costs by $51 Billion Annually, Report Finds

1 hour ago

Beware of Scammers Saying You Won the Publishers Clearing House Drawing

2 hours ago

Abundance Meets Resistance: Are CA Dems Finally Ready to Go All In on Building Housing?

2 hours ago

Less Than Half of Californians Think K-12 Schools Are on the Right Track: Poll

2 hours ago

Yastrzemski and Chapman Homers Help Giants Rally Past the Brewers

16 hours ago

Fresno City Council Finally Passes a Tough Smoke Shop Ordinance

16 hours ago

49ers Draft Georgia Edge Rusher Mykel Williams With the No. 11 Pick in the NFL Draft

SANTA CLARA, Calif. — With gaping holes on their defensive line depth chart, the San Francisco 49ers had one major target in mind headed int...

2 minutes ago

2 minutes ago

49ers Draft Georgia Edge Rusher Mykel Williams With the No. 11 Pick in the NFL Draft

President Donald Trump speaks at the National Prayer Breakfast at the Capitol in Washington, Feb. 6, 2025. (AP File)
14 minutes ago

Trump’s Immigration Approval Ratings Decline as Enforcement Tactics Lose Support

A Fresno man was arrested in Kerman on Wednesday, April 23, 2025, after allegedly driving recklessly, resisting arrest, and showing signs of being under the influence, police said. (Kerman PD)
19 minutes ago

Fresno Man Tased, Arrested After Suspected Reckless DUI in Kerman

A pedestrian was killed in a traffic collision early Monday morning in Madera, and police are asking for witnesses to come forward.
34 minutes ago

Madera Vehicle Burglary Leads to Arrests, Gang Charges for Juveniles

46 minutes ago

Why Texas Is Ahead of California on Bilingual Education

Demonstrators hold a banner during a "Stand Up for Internationals" rally on the campus of Berkeley University in Berkeley, California, U.S., April 17, 2025. (REUTERS/Carlos Barria/File Photo)
1 hour ago

US Universities Help Foreign Students Weather Trump Deportations

1 hour ago

Alphabet Says Waymo May Offer Robotaxis for Personal Ownership in Future

U.S. dollar banknote and medicines are seen in this illustration taken, June 27, 2024. (REUTERS/Dado Ruvic/Illustration//File Photo)
1 hour ago

US Pharma Tariffs Would Raise US Drug Costs by $51 Billion Annually, Report Finds

Help continue the work that gets you the news that matters most.

Search

Send this to a friend