SUBSCRIBE
Tech Journal Now
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
Reading: Chrome extension privacy promises undone by hardcoded secrets, leaky HTTP
Share
Tech Journal NowTech Journal Now
Font ResizerAa
  • News
  • Reviews
  • Guides
  • AI
  • Best Buy
  • Games
  • Software
Search
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Tech Journal Now > Software > Chrome extension privacy promises undone by hardcoded secrets, leaky HTTP
Software

Chrome extension privacy promises undone by hardcoded secrets, leaky HTTP

News Room
Last updated: June 9, 2025 2:12 pm
News Room
Share
1 Min Read
SHARE

From the extensions Guo mentioned, SEMRush Rank and PI Rank transmit users’ full browsing domains in plaintext to rank.trellian.com, effectively exposing their web activity. MSN New Tab/Homepage sends a persistent Machine ID, OS version, and extension version using an unencrypted SendPingDetails request, data that can be used to track users across sessions.  

Additionally, DualSafe Password Manager, while not leaking passwords, still pushes analytics like browser language and version to stats.itopupdate.com over HTTP.  

“We used to call these (extensions) BHO’s – browser helper objects – and this was a very common way to compromise browsers for various outcomes, ranging from stealing credentials and spying on users, to simply establishing ways to very uniquely identify and track users across the internet,” said BugCrowd CISO Trey Ford. “Ultimately, this can manifest as a form of malware, and unavoidably create a new attack surface for miscreants to attack and compromise a very secure browsing experience.” 

Read the full article here

You Might Also Like

May’s Patch Tuesday serves up 78 updates, including 5 zero-day fixes – Computerworld

Microsoft 365 apps on Windows 10 to get security updates until 2028 – Computerworld

4 essential facts about Android 16’s Advanced Protection security supermode – Computerworld

How to discover hidden tech talent in your organization

the key to high-performing IT teams – Computerworld

Share This Article
Facebook Twitter Email Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Trending Stories

Games

‘We need to do a better job’: FBC Firebreak devs are revamping progression after finding out that just 5% of players own a level 3 perk

July 3, 2025
Games

Persona 5: The Phantom X has blessed the community with a new sh**posting mascot so corny it eclipses the nuance around the real-world issues he represents

July 3, 2025
Games

Final Fantasy 14 is fast-tracking one of my most-anticipated fixes, releasing an entire month earlier than expected

July 3, 2025
Games

Today’s Wordle answer for Thursday, July 3

July 3, 2025
Software

Microsoft’s Exchange Server Subscription Edition now GA to replace standalone Exchange 2016 and 2019 – Computerworld

July 3, 2025
Games

‘It’s not like we applied for the award ourselves’: Dave the Diver director reminds people that ‘there’s nothing indie’ about his game and the controversial indie nomination was out of his control

July 3, 2025

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

Follow US on Social Media

Facebook Youtube Steam Twitch Unity

2024 © Prices.com LLC. All Rights Reserved.

Tech Journal Now

Quick Links

  • Privacy Policy
  • Terms of use
  • For Advertisers
  • Contact
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?