Vulnerabilities / Threats
9/29/2011
01:01 PM
50%
50%

Top Google Chrome Extensions Leak Data

Study of 100 extensions found that 27% leave users vulnerable to Web or Wi-Fi attack.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
A review of 100 Google Chrome extensions, including the 50 most popular selections, found that 27% of them contain one or more vulnerabilities that could be exploited by attackers either via the Web or unsecured Wi-Fi hotspots.

Those findings come from a study being conducted by security researchers Adrienne Porter Felt, Nicholas Carlini, and Prateek Saxena at University of California, Berkeley. In particular, they analyzed the 50 most popular Chrome extensions, as well as 50 others selected at random, for JavaScript injection vulnerabilities, since such bugs can enable an attacker to take complete control of an extension.

The researchers found that 27 of the 100 extensions studied contained one or more injection vulnerabilities, for a total of 51 vulnerabilities across all of the extensions. The researchers also said that seven of the vulnerable extensions were used by 300,000 people or more.

"Bugs in extensions put users at risk by leaking private information (like passwords and history) to Web and Wi-Fi attackers," they said. "Websites may be evil or contain malicious content from users or advertisers. Attackers on public Wi-Fi networks (like in coffee shops and airports) can change all HTTP content."

[ Threats can come from many different routes. Learn how Social Engineering Attacks Pose As Corporate Copiers ]

The researchers sent vulnerability warnings to all relevant developers, and so far two related patches have been released. One involved Twitter's Silver Bird extension (version 1.9.7.9), which had a vulnerability that an attacker could use to hide scripts in the data feed sent to Twitter, although the micro-blogging service appears to sanitize all incoming data against attack. Regardless, the vulnerability was fixed with the release of version 1.9.8.4 of Silver Bird.

Another vulnerability was resolved by Google updating OpenAttribute--used to help people read websites' Creative Commons (CC) licenses--from version 0.6 to 0.7, with the new version locking down the extension's security. According to the Berkeley team's OpenAttribute extension vulnerability disclosure to Google in July, a successful exploit of the vulnerability could allow an attacker to spoof a user's identity when making HTTP requests. In addition, they said, "a malicious website could serve a fake CC license that includes inline scripts, or a Wi-Fi attacker could insert inline scripts into a license provided by a legitimate website like Wikipedia. The inserted code then runs in the extension's popup window with the extension's privileges."

The extension vulnerabilities detailed to date are part of a larger study into Google Chrome security. The full study, to be released in two months, will name and include full details about all of the vulnerable extensions discovered. "We haven't released all of the vulnerable extension names because some of the very popular ones are still unpatched, and we're giving them some time to get fixed," according to a blog post from security researcher Adrienne Porter Felt at Berkeley.

The interest in browser extension security reflects the fact that as browser makers--including Microsoft--have become more adept at securing their code (to say nothing of Microsoft also improving Windows security), attackers have turned their attention to exploiting vulnerabilities in the third-party code--including add-ons and extensions--used by browsers.

Security professionals often view compliance as a burden, but it doesn't have to be that way. In this report, we show the security team how to partner with the compliance pros. Download the report here. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
YMOM100
50%
50%
YMOM100,
User Rank: Apprentice
10/26/2011 | 9:04:16 AM
re: Top Google Chrome Extensions Leak Data
Why don't you write out the extensions that you've found leak data?! Does't say anything in the report either!
jrapoza
50%
50%
jrapoza,
User Rank: Apprentice
9/29/2011 | 8:52:56 PM
re: Top Google Chrome Extensions Leak Data
How does this compare with Firefox and its many extensions? Would Firefox do worse (there have definitely been past examples of Firefox extensions with security issues), would it do better, or worse?
To a certain degree, as with mobile app stores and general operating systems, there is a certain amount of risk with anything that you install to your browser.

Jim Rapoza is an InformationWeek Contributing Editor
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8142
Published: 2014-12-20
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys w...

CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.