A new attack called 'Browser Syncjacking' demonstrates the possibility of using a seemingly benign Chrome extension to take over a victim's device. The new attack method, discovered by security researchers at SquareX, involves several steps, including Google profile hijacking, browser hijacking, and, eventually, device takeover. Despite the multi-stage process, the attack is stealthy, requires minimal permissions, and almost no victim interaction other than to install what appears to be a legitimate Chrome extension. The attack begins with the creation of a malicious Google Workspace domain where the attacker sets up multiple user profiles with security features such as multi-factor authentication disabled. This Workspace domain will be used in the background to create a managed profile on the victim's device. A browser extension, made to appear as a useful tool with legitimate functionality, is then published on the Chrome Web Store. Using social engineering, the attacker tricks the victim into installing the extension, which then quietly logs them into one of the attacker's managed Google Workspace profiles in a hidden browser window running in the background. The extension then opens a legitimate Google support page. As it has Read and Write privileges to webpages, it injects content into the page, telling the user to enable Chrome sync. Once synced, all stored data, including passwords and browsing history, becomes accessible to the attacker, who can now use the compromi...
New Syncjacking attack hijacks devices using Chrome extensions
BleepingComputer
·Bill Toulas
·Published Jan 30, 2025
·Updated
Affected Software
3 affected components
Google Chrome
Google Chrome Web Store
Google Chrome
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a new security attack known as 'Browser Syncjacking' that exploits Chrome extensions to hijack devices.
2
What security implications are discussed?
The article highlights the risk of malicious Chrome extensions being used to take over a user's device and manipulate their browser settings.
3
What products or software are affected?
The affected software includes Google Chrome and the Google Chrome Web Store.
4
Who discovered this new attack method?
The attack method was discovered by security researchers at SquareX.
5
How does the Browser Syncjacking attack exploit users?
The attack exploits seemingly benign Chrome extensions to gain unauthorized access and control over the victim's device.