{"id":3262,"date":"2025-06-06T20:07:45","date_gmt":"2025-06-06T20:07:45","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=3262"},"modified":"2025-06-06T20:07:45","modified_gmt":"2025-06-06T20:07:45","slug":"widespread-chrome-extensions-discovered-leaking-information-through-unencrypted-connections","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=3262","title":{"rendered":"Widespread Chrome Extensions Discovered Leaking Information through Unencrypted Connections"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>A current investigation has revealed that a number of extensively used <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/500-google-chrome-extensions-spreading-malware\/\" target=\"_blank\" data-type=\"post\" data-id=\"75602\" rel=\"noreferrer noopener\">Google Chrome extensions<\/a> are transmitting delicate person information over unencrypted HTTP connections, exposing hundreds of thousands of customers to critical privateness and safety dangers.<\/p>\n<p>The findings, revealed by cybersecurity researchers and detailed in a weblog put up by Symantec, reveal how extensions corresponding to: <\/p>\n<p>PI Rank <code>(ID: ccgdboldgdlngcgfdolahmiilojmfndl)<\/code><\/p>\n<p>Browsec VPN <code>(ID: omghfjlpggmjjaagoclmmobgdodcjboh<\/code>)<\/p>\n<p>MSN New Tab <code>(ID: lklfbkdigihjaaeamncibechhgalldgl)<\/code><\/p>\n<p>SEMRush Rank (<code>ID: idbhoeaiokcojcgappfigpifhpkjgmab<\/code>)<\/p>\n<p>DualSafe Password Supervisor &amp; Digital Vault <code>(ID: lgbjhdkjmpgjgcbcdlhkokkckpjmedgc)<\/code> <\/p>\n<p>There are different extensions as nicely which can be dealing with person information in ways in which open the door to eavesdropping, profiling, and different assaults.<\/p>\n<h3 id=\"extensions-that-promise-privacy-are-doing-the-opposite\" class=\"wp-block-heading\"><strong>Extensions That Promise Privateness Are Doing the Reverse<\/strong><\/h3>\n<p>Though these extensions are professional and meant to assist customers monitor internet rankings, handle passwords, or enhance their looking expertise, behind the scenes, they&#8217;re making community requests with out encryption, permitting anybody on the identical community to see precisely what\u2019s being despatched.<\/p>\n<p>In some circumstances, this consists of particulars just like the domains a person visits, working system data, distinctive machine IDs, and telemetry information. Extra troubling, a number of extensions had been additionally discovered to have <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/payment-api-vulnerabilities-expose-transaction-keys\/\" data-type=\"post\" data-id=\"87938\" target=\"_blank\" rel=\"noreferrer noopener\">hardcoded API keys<\/a>, secrets and techniques, and tokens inside their supply code which is a bit of useful data that attackers can simply exploit.<\/p>\n<h3 id=\"real-risk-on-public-networks\" class=\"wp-block-heading\"><strong>Actual Danger on Public Networks<\/strong><\/h3>\n<p>When extensions transmit information utilizing <code>HTTP<\/code> fairly than <code>HTTPS<\/code>, the data travels throughout the community in plaintext. On a public Wi-Fi community, for instance, a malicious actor can intercept that information with little effort. Worse nonetheless, they will modify it mid-transit.<\/p>\n<p>This opens the door to assaults that go far past spying. In response to Symantec\u2019s <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.security.com\/threat-intelligence\/chrome-extension-leaks\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">weblog put up<\/a>, within the case of Browsec VPN, a well-liked privacy-focused extension with over six million customers, the usage of an HTTP endpoint in the course of the uninstall course of sends person identifiers and utilization stats with out encryption. The extension\u2019s configuration permits it to connect with insecure web sites, additional widening the assault floor.<\/p>\n<h3 id=\"data-leaks-across-the-board\" class=\"wp-block-heading\"><strong>Information Leaks Throughout the Board<\/strong><\/h3>\n<p>Different extensions are responsible of comparable points. SEMRush Rank and PI Rank, each designed to point out web site recognition, had been discovered to ship full URLs of visited websites over <code>HTTP<\/code> to third-party servers. This makes it straightforward for a community observer to construct detailed logs of a person\u2019s looking habits.<\/p>\n<p>MSN New Tab and MSN Homepage, with a whole bunch of hundreds of customers, transmit machine IDs and different gadget particulars. These identifiers stay steady over time, permitting adversaries to hyperlink a number of periods and construct profiles that persist throughout looking exercise.<\/p>\n<p>Even DualSafe Password Supervisor, which handles delicate data by nature, was caught sending telemetry information over <code>HTTP<\/code>. Whereas no passwords had been leaked, the truth that any a part of the extension makes use of unencrypted visitors raises issues about its total design.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.linkedin.com\/in\/patrick-tiquet-1ba9b497\" target=\"_blank\" rel=\"noreferrer noopener\">Patrick Tiquet<\/a>, Vice President, Safety &amp; Structure at Keeper Safety commented on this, stating, <em>\u201c<\/em>This incident highlights a crucial hole in extension safety \u2013 even widespread Chrome extensions can put customers in danger if builders minimize corners. Transmitting information over unencrypted HTTP and hard-coding secrets and techniques exposes customers to profiling, phishing and adversary-in-the-middle assaults \u2013 particularly on unsecured networks.<em>\u201c<\/em><\/p>\n<p>He warned of penalties for unsuspecting customers and suggested that <em>\u201c<\/em>Organizations ought to take speedy motion by imposing strict controls round browser extension utilization, managing secrets and techniques securely and monitoring for suspicious behaviour throughout endpoints.<em>\u201c<\/em><\/p>\n<h3 id=\"privacy-and-data-security-threat\" class=\"wp-block-heading\"><strong>Privateness and Information Safety Menace<\/strong><\/h3>\n<p>Though not one of the extensions had been discovered to leak passwords or monetary information straight, the publicity of machine identifiers, looking habits, and telemetry is much from innocent. Attackers can use this information to trace customers throughout web sites, ship focused phishing campaigns, or impersonate gadget telemetry for malicious functions.<\/p>\n<p>Whereas theoretical, NordVPN\u2019s newest findings noticed greater than <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/nearly-94-billion-stolen-cookies-on-dark-web\/\" target=\"_blank\" rel=\"noreferrer noopener\">94 billion browser cookies on the darkish internet<\/a>. When mixed with the information leaks highlighted by Symantec, the potential for harm is critical.<\/p>\n<p>Builders who embody hardcoded API keys or secrets and techniques inside their extensions add one other layer of danger. If an attacker will get maintain of those credentials, they will misuse them to impersonate the extension, ship solid information, and even inflate service utilization resulting in monetary prices or account bans for the builders.<\/p>\n<h3 id=\"what-users-can-do\" class=\"wp-block-heading\"><strong>What Customers Can Do<\/strong><\/h3>\n<p>Symantec has contacted the builders concerned, and solely DualSafe Password Supervisor has mounted the difficulty. But, customers who&#8217;ve put in any of the affected extensions are suggested to take away them till the builders repair the problems. Even widespread and well-reviewed extensions could make unsafe design decisions that go unnoticed for years.<\/p>\n<p>Hckread.com recommends checking the permissions an extension asks for, avoiding unknown publishers, and utilizing a trusted safety resolution. Above all, any device that guarantees privateness or safety must be examined fastidiously for the way it handles your information.<\/p>\n<p>\n\t\t\t<\/div>\n<p><template id="sHxOCGkylJuQQB2h1wDg"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A current investigation has revealed that a number of extensively used Google Chrome extensions are transmitting delicate person information over unencrypted HTTP connections, exposing hundreds of thousands of customers to critical privateness and safety dangers. The findings, revealed by cybersecurity researchers and detailed in a weblog put up by Symantec, reveal how extensions corresponding to: [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":3264,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[1624,2285,157,215,2767,189,3093],"class_list":["post-3262","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-chrome","tag-connections","tag-data","tag-extensions","tag-leaking","tag-popular","tag-unencrypted"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/3262","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3262"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/3262\/revisions"}],"predecessor-version":[{"id":3263,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/3262\/revisions\/3263"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/3264"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3262"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3262"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3262"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-13 15:16:31 UTC -->