City
Epaper

Malicious Chrome sync feature can help hackers steal your data

By IANS | Updated: February 7, 2021 10:50 IST

New Delhi, Feb 7 A cyber security researcher has discovered a malicious Google Chrome extension in the wild ...

Open in App

New Delhi, Feb 7 A cyber security researcher has discovered a malicious Google Chrome extension in the wild abusing the Chrome Sync process that can help hackers steal user data.

Hackers can use the Google Chrome sync feature to send commands to infected browsers and steal data from infected systems, bypassing traditional firewalls and other network defenses.

Croatian security researcher Bojan Zdrnja found a malicious Chrome extension that can communicate with a remote command and control (C&C) server and as a way to exfiltrate data from infected browsers, reports ZDNet.

Chrome sync is a feature of the Chrome web browser that stores copies of a user's Chrome bookmarks, browsing history, passwords, and browser and extension settings on Google's cloud servers.

According to Zdrnja, the goal was to use the extension to "manipulate data in an internal web application that the victim had access to."

"While they also wanted to extend their access, they actually limited activities on this workstation to those related to web applications, which explains why they dropped only the malicious Chrome extension, and not any other binaries," Zdrnja said in the report.

The basis for this attack were malicious extensions that the attacker dropped on the compromised system.

"Now, malicious extensions are nothing new – there were a lot of analysis about such extensions and Google regularly removes dozens of them from Chrome Web Store, which is the place to go to in order to download extensions," the security researcher mentioned.

( With inputs from IANS )

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: C&CBojan zdrnjagoogleWord on macWho dgMicrosoft incUs google & youtubeSk duaDan patel
Open in App

Related Stories

TechnologyIPL 2026 Google Doodle: Search Engine Giant Rolls Out Neon-Themed Doodle to Celebrate Start of Indian Premier League

TechnologyWhy YouTube Witness Global Outage? TeamYouTube Reveals Reason

TechnologyYouTube Down: TeamYouTube Says Its Teams Are Looking Into Global Outage

TechnologyRamadan 2026 Moon Sighting Google Doodle: Search Engine Rolls Out ‘Search Crescent Moon’ Game to Wish Ramadan Kareem

TechnologyTech Giants Plan $650 Billion AI Investment in 2026 to Dominate Global Market

Technology Realted Stories

TechnologyEV charging hub unveiled at Anand Vihar Namo Bharat Station, 10 vehicles can be charged simultaneously

TechnologyAmaravati to be growth engine for $2.4 trillion economy: Andhra CM​

TechnologyJan Vishwas Bill, 2026 decriminalises minor offences in health sector

TechnologyFood prices to rise further globally if West Asia crisis stretches beyond 40 days: FAO

TechnologyGoogle now allow Gmail users to change their usernames