New exploits are tricking Chrome. [Research Saturday]

Published: March 4, 2023, 8 a.m.

Dor Zvi, Co-Founder and CEO from Red Access to discuss their work on "New Chrome Exploit Lets Attackers Completely Disable Browser Extensions." A recently patched exploit is tricking Chrome browsers on all popular OSs to not only give attackers visibility of their targets\u2019 browser extensions, but also the ability to disable all of those extensions.\nThe research states the exploit consists of a bookmarklet exploit that allows threat actors to selectively force-disable Chrome extensions using a handy graphical user interface making Chrome mistakenly identify it as a legitimate request from the Chrome Web Store.\nThe research can be found here:\nNew Chrome Exploit Lets Attackers Completely Disable Browser Extensions\n\nLearn more about your ad choices. Visit megaphone.fm/adchoices