10:32 AM

Google Chrome Tabs Let Malware Sneak Into Businesses

Enterprises need to watch for "bring your own browser" attacks. Using Google Chrome tabs, malware could piggyback into a corporate environment in two ways.

Google Drive: 10 Alternatives To See
Google Drive: 10 Alternatives To See
(click image for larger view and for slideshow)
Google Chrome users: Watch your sync habits. The browser's ability to synchronize tabs across different computers could be used by a malicious attacker to eavesdrop on personal or corporate communications.

The tab-synchronization capability appeared last month in the latest version of the Google Chrome browser, and allows users to synchronize their open browser tabs across devices. As a result, users can log into any version of the Google Chrome browser--on home PCs, work PCs, or mobile devices--and access their saved tabs.

Unfortunately, the same would go for malware. "Consider the following scenario: The user is signed in to Chrome on both work and home computer. ... The home computer gets infected by a malware. Now all of the work synced data (such as work-related passwords) is owned by the malware," said Rob Rachwald, director of security strategy at Imperva, in a blog post.

"We name this kind of threats BYOB for 'Bring Your Own Browser,'" he said. "While BYOD creates challenges of mixing work data and personal end points, BYOB does exactly the same--but it's more elusive as there's no physical device involved."

Furthermore, IT departments could have difficulty successfully spotting and blocking malware that infiltrates the enterprise in this manner, especially given the number of attacks that could be launched from an infected home PC. "Even if the malware gets disinfected on work computer, the malware is able to infect over and over again--as the root cause of the infection--the home computer--is outside of the reach of the IT department," Rachwald said.

Two Ways In

Google didn't immediately respond to a request for comment about the feasibility of this attack, or steps that users could take to mitigate this type of threat. To be sure, this is a theoretical attack; no such Chrome-targeting malware campaign has been seen in the wild. But malware could potentially piggyback into a corporate environment, using Chrome tabs, in two ways.

The first exploit technique would be if "the malware changes the homepage or some bookmark to point to a malware-infection site on the home computer," said Rachwald. "Settings are synced to your work environment. When you open your browser at work, you get infected with some zero-day drive-by download." In this scenario, attackers could instruct the malware to keep attacking the corporate network, and even vary the attack being used, in an attempt to evade defenses. This would be difficult for a business to stop with complete reliability.

"Even if the malware gets disinfected on work computer, the malware is able to infect over and over again, as the root cause of the infection--the home computer--is outside of the reach of the IT department," he said.

Another potential attack vector would be if the malware installed a rogue Chrome extension, and such extensions have appeared on the official Chrome Web Store in the past. As Google notes, "anyone can upload items to the Chrome Web Store, so you should only install items created by people you trust," and by reviewing the ratings and reviews for an extension to help deduce whether it's reliable. Google quickly removes any malicious Chrome extensions, once they're spotted. But until that happens, any malicious extension is able to operate with impunity.

"Chrome extensions are evil," noted Felix "FX" Lindner, head of Recurity Labs in Berlin. That comment came during a talk he delivered at Black Hat Europe earlier this year, in which he highlighted how Chrome extensions can be used by an attacker to inject JavaScript directly into the browser. What's more, any users who sign into Chrome on a different workstation will have their extensions automatically installed on the current PC. As a result, a malicious extension installed at home could easily appear on a workplace PC, creating a vulnerability similar to the one that Rachwald highlighted.

Why are malicious Chrome extensions so dangerous? "If you have an extension installed, it has ... pretty much omnipotent control over your Chrome browser," said Lindner, speaking by phone. "Google tries to prevent the extension from accessing your extension manager, but we've found ways to do it. Google fixed them, but I'm pretty confident that there are other ways."

Preventing users from installing Chrome extensions is nearly impossible. For starters, while the IT department can issue its own Chrome build, and set it to block extensions, you can install and run your own installation of the browser on any PC for which you have permission to write to the home directory--no administrator rights required.

Security defenses also won't spot malicious extensions. "This all being JavaScript and HTML, the corporate antivirus is not going to catch it--on top of the fact that you're downloading the extension via SSL from Google's Web store," said Lindner. "Unless corporate [IT] breaks SSL for you, they're not going to see it anyway.

Since the browser's preferences are handled with JavaScript, a malicious extension could automatically--and without a user being aware--install and run arbitrary code in the browser. For example, the extension might unleash a Trojan application that recorded everything the user did, or open a malicious website in the browser. Furthermore, if this extension was first installed at home, it would automatically get pushed to work when the user logged in there.

Attackers aren't the only concern for Chrome users, as the Google tab synchronization feature could also be used during digital forensic investigations. "Imagine there's a case against you at work, and they do forensics, and they get all of your accounts at home," said Lindner.

But the bigger picture, he said, is that users should consider the security implications of synchronizing information between Chrome tabs or even between Google services. "I'm really not sure who would want to: a) give all this information to Google, and then, b) actually sync it onto every single machine they're using," Lindner said. "So much for defense. But maybe I'm the wrong person to ask--I don't even have a Google account. Wrong religion."

Employees and their browsers might be the weak link in your security plan. The new, all-digital Endpoint Insecurity Dark Reading supplement shows how to strengthen them. (Free registration required.)

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Apprentice
6/1/2012 | 6:20:51 PM
re: Google Chrome Tabs Let Malware Sneak Into Businesses
Yet another reason NOT to trust Google when it comes to security and/or protection of your personal information. btw - IE10 will be shipped with "Do Not Track" enabled by default. Try getting Google to help you out with that...
Register for Dark Reading Newsletters
White Papers
Current Issue
Dark Reading Tech Digest September 7, 2015
Some security flaws go beyond simple app vulnerabilities. Have you checked for these?
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-02
Buffer overflow in Canary Labs Trend Web Server before 9.5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet.

Published: 2015-10-02
Cisco NX-OS 6.0(2)U6(0.46) on N3K devices allows remote authenticated users to cause a denial of service (temporary SNMP outage) via an SNMP request for an OID that does not exist, aka Bug ID CSCuw36684.

Published: 2015-10-02
Cisco Email Security Appliance (ESA) 8.5.6-106 and 9.6.0-042 allows remote authenticated users to cause a denial of service (file-descriptor consumption and device reload) via crafted HTTP requests, aka Bug ID CSCuw32211.

Published: 2015-10-01
lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.

Published: 2015-10-01
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.

Dark Reading Radio
Archived Dark Reading Radio
What can the information security industry do to solve the IoT security problem? Learn more and join the conversation on the next episode of Dark Reading Radio.