Новости компьютерной безопасности:

  Latest News

Chrome Extensions Vulnerability Exposes API Keys, Secrets, and Tokens

С сайта: Vulnerability(cybersecuritynews.com)

Chrome Extensions Vulnerability Exposes API Keys, Secrets, and Tokens

Author: Tushar Subhra Dutta

A significant security vulnerability affecting millions of Chrome extension users has been discovered, revealing widespread exposure of sensitive API keys, secrets, and authentication tokens directly embedded in extension code.

This critical flaw stems from developers hardcoding credentials into their JavaScript files, making these secrets accessible to anyone who inspects the extension packages.

The vulnerability affects popular extensions with millions of combined users, potentially exposing cloud services, analytics platforms, and other third-party integrations to unauthorized access and abuse.

The security oversight represents one of the most fundamental mistakes in modern software development, where sensitive authentication materials are stored in plain text within client-side code.

Once Chrome extensions are published to the Web Store, their source code becomes readily available for inspection, effectively broadcasting these credentials to potential attackers.

The implications extend far beyond simple data exposure, as malicious actors can leverage these credentials to spam analytics services, incur unauthorized cloud computing costs, upload malicious content, or gain broader access to connected services depending on the permissions associated with each compromised key.

Symantec researchers identified this widespread vulnerability while conducting routine security assessments of popular browser extensions, uncovering a pattern of poor credential management practices across multiple high-profile extensions.

The discovery highlights a systemic issue in extension development practices, where convenience often supersedes security considerations.

The affected extensions collectively serve over 15 million users, making this one of the largest credential exposure incidents in recent browser extension history.

The vulnerability’s impact varies significantly depending on the type and scope of exposed credentials, ranging from corrupted analytics data to potential financial losses for extension developers whose cloud services become targets for abuse.

More concerning is the possibility that attackers could use compromised AWS credentials or similar cloud service keys to pivot into broader infrastructure, potentially accessing databases, file storage systems, or other connected resources if the credentials possess elevated permissions.

Technical Analysis of Credential Exposure Patterns
The exposed credentials follow distinct patterns across different extension categories, with analytics keys, cloud storage credentials, and speech recognition API tokens representing the most common vulnerabilities.

In the case of Avast Online Security & Privacy and AVG Online Security extensions, hardcoded Google Analytics 4 API secrets appear directly in JavaScript variables.

cyber security newsCode snippets showing hardcoded Google Analytics 4 (GA4) API secrets (Source – Security)
The code snippet var GA4_API_SECRET = "2y-Q"; demonstrates how these secrets are appended to analytics URLs, enabling attackers to flood GA4 endpoints with fraudulent events and corrupt metrics data.

Similarly, the Equatio – Math Made Digital extension exposes Azure API keys for speech recognition services through window.equatioAzureApiKey = "48!3";.

This exposure allows malicious users to consume the developer’s Azure subscription resources, potentially resulting in significant unexpected costs.

cyber security newsExposed AWS access key (Source – Security)
The most severe cases involve AWS access keys found in screenshot applications, where the exposed credentials AWSAccessKeyId: "AKIA" could enable attackers to upload malicious content to S3 buckets or access other AWS services if the credentials possess broader permissions.



#Cyber_Security_News #Vulnerability #cyber_security_news #vulnerability

Оригинальная версия на сайте: Chrome Extensions Vulnerability Exposes API Keys, Secrets, and Tokens
Вернуться к списку новостей К свежим новостям Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.

Вернуться к списку новостей Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.


Новости проекта CSN:

✉ CSN.net4me.net

Обновление сайта csn.net4me.net

Обновление сайта csn.net4me.net 💻
cyber security news
  • Физически мы переехали на новый сервер. Благодарим наших подписчиков и постоянных читателей за терпение и понимание.
  • Сайт csn.net4me.net полностью адаптирован для работы по шифрованному SSL соединению.
  • Изменен механизм обработки и отображения опасных и критических уязвимостей.

Благодарим что вы с нами.


#CSN_обновление_сайта
https://csn.net4me.net/cyber_security_8301.html

Дополнительный материал

О проекте CSN

Проект CSN.net4me.net родился 16 Марта 2018 года.
Проект находится в самом начале своего развития. Конечно оформление, наполнение будет меняться. Одно останется неизменным - самые свежие новости компьютерной и сетевой безопасности.

О проекте net4me

Проект net4me.net развивался как сборник готовых решений и документации по темам компьютерной безопасности, сетевых решений и СПО (в часности linux). Темпы развития IT отрасли оказались столь быстрыми, что некоторые знания, технологии и информация о них устаревали мгновенно. Тем не менее, некоторый материал net4me.net до сих пор востребован.

Об источниках

Новости берутся CSN из открытых и доступных каждому источников. Авторы проекта стараются подбирать авторитетные и проверенные источники. Но, тем не менее, не несут ответственности за содержимое новостей. В каждой новости указывается источник этой новости, её автор и ссылка на оригинал новости.

Информация

Если вы желаете чтобы новости вашего ресурса были размещены на сайте CSN, то свяжитесь с авторами проекта csn@net4me.net и предложите ссылку на rss или xml ленту новостей вашего ресурса. Любая предложенная информация будет рассмотрена редакцией.