#browser extension
7 stories taggedbrowser extension.

A Flaw in N-able's Passportal Handed Any Malicious Website the Keys to Every Password a Business Stored
A researcher found that Passportal's browser extension trusted every message it received without question, letting any webpage silently drain a company's entire vault of login credentials.

Millions of Belgians' IDs and bank accounts were wide open through a government browser extension
A browser extension used by more than 2 million Belgians to log into government and banking websites contained flaws so serious that criminals could have stolen identities, hijacked payment cards, and taken full control of victims' computers. The vendor fixed the problems on 22 July.

Meet Jewelbug: The Chinese Hacker-for-Hire Group Stealing Crypto and Spying on Governments at the Same Time
A single criminal outfit is running a massive cryptocurrency scam network with one hand and breaking into Middle Eastern government email systems with the other. Researchers say the group almost certainly works for China.

Fake CCleaner site turns Chrome into a spying and password-theft tool
Criminals built a convincing copycat download page for one of the world's most-downloaded PC tools, then used it to silently hijack Google Chrome and steal passwords, bank details, and screenshots.

Two Million Belgians Exposed by Flaws in the Software They Use to Sign Legal Documents Online
Security researcher James Arnott found that Belgium's most-used digital identity tool could let any malicious website steal a user's PIN, forge their electronic signature, or quietly run attack code on their computer, all without the victim clicking anything suspicious.

A Browser Extension Installed 300 Million Times Had a Flaw That Let Attackers Steal Your WhatsApp Messages
A security hole in Adobe's widely used browser extension meant that simply visiting the wrong website could hand criminals your private messages and contacts.

Bugs in Claude's Chrome Extension Let Other Add-Ons Read Your Gmail and Docs
Security researchers say two unpatched flaws in Anthropic's browser assistant can be exploited to silently pull private data from Google services, and a simple one-line fix has gone unshipped for months.