108 Chrome extensions caught stealing user data and hijacking sessions (opens in new tab)
submitted by beep to cybersecurity1 points | 0 comments 54 extensions steal Google account identity via OAuth2; 1 extension actively exfiltrates Telegram Web sessions every 15 seconds; 1 extension includes staged infrastructure for Telegram session theft (not yet activated); 2 extensions strip YouTube security headers and inject ads; 1 extension strips TikTok security headers and injects ads; 2 extensions inject content scripts into every page the user visits; 1 extension proxies all translat...
Read the original article