• News/
  • https://www.bleepingcomputer.com/news/security/new-syncjacking-attack-hijacks-devices-using-chrome-extensions/

New Syncjacking attack hijacks devices using Chrome extensions

BleepingComputer
·
Bill Toulas
·
Published Jan 30, 2025
·
Updated

A new attack called 'Browser Syncjacking' demonstrates the possibility of using a seemingly benign Chrome extension to take over a victim's device. The new attack method, discovered by security researchers at SquareX, involves several steps, including Google profile hijacking, browser hijacking, and, eventually, device takeover. Despite the multi-stage process, the attack is stealthy, requires minimal permissions, and almost no victim interaction other than to install what appears to be a legitimate Chrome extension. The attack begins with the creation of a malicious Google Workspace domain where the attacker sets up multiple user profiles with security features such as multi-factor authentication disabled. This Workspace domain will be used in the background to create a managed profile on the victim's device. A browser extension, made to appear as a useful tool with legitimate functionality, is then published on the Chrome Web Store. Using social engineering, the attacker tricks the victim into installing the extension, which then quietly logs them into one of the attacker's managed Google Workspace profiles in a hidden browser window running in the background. The extension then opens a legitimate Google support page. As it has Read and Write privileges to webpages, it injects content into the page, telling the user to enable Chrome sync. Once synced, all stored data, including passwords and browsing history, becomes accessible to the attacker, who can now use the compromi...

Read full article

Affected Software

3 affected components
Google Chrome
Google Chrome Web Store
Google Chrome
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new security attack known as 'Browser Syncjacking' that exploits Chrome extensions to hijack devices.

2

What security implications are discussed?

The article highlights the risk of malicious Chrome extensions being used to take over a user's device and manipulate their browser settings.

3

What products or software are affected?

The affected software includes Google Chrome and the Google Chrome Web Store.

4

Who discovered this new attack method?

The attack method was discovered by security researchers at SquareX.

5

How does the Browser Syncjacking attack exploit users?

The attack exploits seemingly benign Chrome extensions to gain unauthorized access and control over the victim's device.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203