A new Chrome browser highjacking attack could affect billions of users – here’s how to fight it


- A new highjacking attack targets Chrome browsers
- It could steal all your browser data and even from your OS
- There are several ways for users to fight back
Whether you believe it to be the best web browser, Google Chrome is undoubtedly the most popular search engine by a landslide. For that reason, it remains a popular target for hackers as well. And now, a massive new threat is on the horizon, which could threaten billions of users.
A new attack called ‘Browser Syncjacking’ has been discovered by security researchers at the cybersecurity firm SquareX (reported on by BleepingComputer). Though it requires several steps, it’s shockingly easy for the average Chrome user to fall victim, as it needs minimal permissions.
First, a malicious Google Workspace domain is created with multiple user profiles, and security features like multi-factor authentication are disabled. This is used to create managed profiles in the background of the victim’s devices. Then, hackers will then create a malicious Chrome extension to launch on the official Chrome Store, appearing as a useful tool to attract potential victims.
Once any potential victims install the extension, it hides a browser window that runs in the background to log the victim into one of the Workspace profiles previously made. The final step involves tricking the victim into activating Chrome sync by opening a very real Chrome support page that’s been tampered with, then guiding them through turning on sync. If this happens, that person’s full Chrome account and stored data — including browsing history and passwords — are now available on the hacker’s profile.
From here, as SquareX explains, a victim’s entire browser can be taken over, often through a seemingly innocent Zoom invite that, if accepted, gets malicious content from that Chrome extension injected into it. If the victim falls for a prompt that asks to update Zoom, the update (actually an executable file that contains an enrollment token) will allow the hacker to control the browser completely.
Not only does this give hackers free reign over any data stored in your browser and allow them to spy on any websites you browse (and see any sensitive information you input), but it also allows them to access your OS to “install malware, capture keystrokes, extract sensitive data and even activate a device’s webcam and microphone,” as Tom’s Guide details.
How do you stay safe?
This all sounds overwhelming and even impossible to avoid since the attacks require so little input from users to get the ball rolling. But there are ways to keep your browser safe from harm.
Sign up for breaking news, reviews, opinion, top tech deals, and more.
The first is to avoid installing new Google Chrome extensions while limiting the ones you already have. If you really need to install anything new, make sure to research it and its developers for signs of suspicious activity.
It’s also essential to have the best antivirus software, which will automatically scan your PC or Mac regularly and immediately alert you to suspicious activity. It’s best to store passwords in the best password managers instead of in the browser, protecting them from hackers’ prying eyes.
There are always new attacks on the horizon, but it’s vital to stay vigilant in your online activity and be careful of extensions and software you download. This will always serve to protect your browser and computer.
A new highjacking attack targets Chrome browsers It could steal all your browser data and even from your OS There are several ways for users to fight back Whether you believe it to be the best web browser, Google Chrome is undoubtedly the most popular search engine by a landslide.…
Recent Posts
- Salt Typhoon hackers used this clever technique to attack US networks
- Apple pulls encryption feature from UK over government spying demands
- Coinbase says the SEC has agreed to drop its crypto lawsuit
- Everything new on Max in March 2024
- Moroi preview: A grimdark action game that’s actually pretty funny
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010