AVG Forces Chrome Extension On Users, Extension Is Woefully Insecure

DEAD7

Veteran
Supporter
Joined
Oct 5, 2012
Messages
51,494
Reputation
4,659
Daps
89,798
Reppin
Fresno, CA.
The AVG Web TuneUp Chrome extension, forcibly added to Google Chrome browsers when users were installing the AVG antivirus, had a serious flaw that allowed attackers to get the user's browsing history, cookies, and more. "This extension adds numerous JavaScript APIs to Chrome, apparently so that they can hijack search settings and the new tab page," explains Mr. Ormandy. "The installation process is quite complicated so that they [AVG] can bypass the Chrome [Store] malware checks, which specifically tries to stop abuse of the [Chrome] Extension API." Simple XSS and MitM attacks expose data from other tabs opened in the browser, browsing history, and even manage to render SSL useless.
 

Jello Biafra

A true friend stabs you in the front
Supporter
Joined
May 16, 2012
Messages
46,184
Reputation
4,958
Daps
120,924
Reppin
Behind You
Look at all the stuff it says it will have access to before installing:
DKipm8Q.png
 
Top