Google purges bad extensions from Chrome
Tens of millions of users who visit Google sites use a browser loaded with malicious add-ons, research suggests.
Most rogue extensions bombard people with ads, but the most malicious steal login names and other valuable data.
Carried out by security experts and Google, the project analysed more than 100 million visits to the search giant's sites.
It led to Google purging almost 200 bad extensions from its online catalogues of browser add-ons.
Extensions and add-ons for web browsers add all kinds of functions and features to the software.
Many of these extensions have hidden extras that cause trouble for people who install them, said UC Santa Barbara computer scientist Alexandros Kapravelos, who worked with Google on the rogue extensions project.
The research found that malicious extensions were available for every major browser.
The findings are due to be published in full in May at the IEEE Symposium on Security and Privacy.
Preliminary results revealed that 5% of people accessing Google every day have been caught out by at least one malicious extension.
Of these victims, about a third have four or more bad add-ons installed in their browser.
"It is a very hard problem to deal with," said Mr Kapravelos.
Some bad extensions were easy to spot, he said, because they were so obviously written to steal saleable data such as bitcoins, bank logins or personal data.
However, many used techniques seen in legitimate extensions, he said, and it took a lot of extra analysis to pin down the bad ones.
"Even when we have a complete understanding of what the extension is doing, sometimes it is not clear if that behaviour is malicious or not," he said.
"You would expect that an extension that injects or replaces advertisements is malicious, but then you have AdBlock that creates an ad-free browsing experience and is technically very similar."
Experts from Swedish security firm ScrapeSentry said it had found examples of extensions that gathered data in ways that could easily be abused.
ScrapeSentry's analysis of one extension, called Webpage Screenshot, revealed that it contained code that let it grab copies of all the browser traffic from the PC on which it was installed.
The gathered data was then sent to a server in the US. The extension has been downloaded about 1.2 million times.
"What happens to the personal data and the motives for sending it to the US server is anyone's guess, but we'd take an educated guess that it's not going to be good news," said Martin Zetterlund from ScrapeSentry.
A spokesman for Webpage Screenshot said there was nothing malicious about the data it gathered.
Instead, said the spokesman, it was used to understand who the extension's users were and where they were located to help drive development of the code.
Users could opt out of sharing data, he said.
Videos
Interview with Francis Malige, EBRD Managing Director
Armenians Commemorating 106th Anniversary of Genocide
Biden Under Pressure to Recognize Armenian Genocide - KTLA 5 News
Governance and Oversight Capacities Account for Our Bank's Robust Management System - Philip Lynch, Independent Board Member at Ameriabank
'Mr. President, It Is Now in Your Power to Right Decades of Denial' - US Congressman Adam Schiff Urges Joe Biden to Recognize Armenian Genocide
Armenians of Nagorno-Karabakh in Despair After Trauma of Military Defeat - France 24
Interview with Kakhaber Kiknavelidze, an Independent Member of Ameriabank Board of Directors
Only Terrorists Keep Hostages, Putting Forward Preconditions for Their Release - Edmon Marukyan
Rep Adam Schiff Says Congress Should Recognize Artsakh
UN's Guterres Issues Global Appeal to Make 2021 'Year of Healing'
NASA's Mars 2020 Perseverance Rover Landing Animations
Azerbaijan Uses Prohibited Phosphorus Chemical Munitions - Defense Army Video
Artsakh Defense Army Units Neutralizing Azerbaijani Arms Supplies
Artsakh Defense Army Units Neutralizing Azerbaijani Drone
Nagorno-Karabakh's Status Has Been At the Heart of Our Approach - Zohrab Mnatsakanyan
Artsakh Defense Army Releases Video Featuring Damaged Azerbaijani Military Equipment
Artsakh Defense Army Units Inflicting Manpower Losses on Azerbaijan
Gas Pipeline Damaged in Azerbaijani Fire Targeting Nagorno-Karabakh's Capital
President Armen Sarkissian Meets Emmanuel Macron at Élysée Palace
Artsakh Defense Army Neutralizes Azerbaijani Military Hardware
Artsakh Defense Army Units Neutralizing Azerbaijani Military Infrastructures
President Armen Sarkissian Meets with NATO Secretary-General in Brussels
Buildings and Homes Lying in Ruins in Nagorno-Karabakh's Capital After Azerbaijani Shelling
Artsakh Defense Army's Precision Fire Gives Deadly Blow to Enemy
Artsakh Defense Army Units Destroying Azerbaijani Tank
Zohrab Mnatsakanyan: Ceasefire Does not Mandate Azerbaijan to Kill Civilians and Hit Civilian Settlements
Armenians Protest Outside Turkrish Embassy in Los Angeles
Losses in Azerbaijan's Military Featured in Defense Army Footage
Artsakh Defense Army Neutralizing Adversary's Transport Column
Turkey openly backs Azerbaijan 'far more aggressively than in the past' - ABC News on Syrian mercenaries fighting in Karabakh
Iconic Armenian Church Hit in Azerbaijani Attacks in Nagorno-Karabakh City (photos)
Artsakh Defense Army Continues High-Precision Strikes
War Situation in Karabakh on European Parliament's Agenda
Call for Urgent Action: Armenian Journalist Brings Intn'l Colleagues' Attention to Situation iin Artsakh After Azerbaijani Attacks
Turkey's Support to Syrian Mercenaries Fighting Against Artsakh: Facts About Azerbaijani Aggression
Nagorno-Karabakh's Capital Under Azerbaijani Strikes
Armenian Armed Forces Neutralize Azerbaijani Defense Positions
ArmenianTroops Destroy Azerbaijani Armored Fighting Vehicle on Frontline
There is a solid evidence that Azerbaijan has launched a thoroughly planned attack on the NKR
EU calls for Immediate End to Hostilities over Nagorno-Karabakh
- 15:20 • 24.05.21 Interview with Francis Malige, EBRD Managing Director
- 11:39 • 24.04.21 Armenians Commemorating 106th Anniversary of Genocide
- 09:40 • 23.04.21 Biden Under Pressure to Recognize Armenian Genocide - KTLA 5 News
- 15:34 • 22.04.21 Governance and Oversight Capacities Account for Our Bank's Robust Management System - Philip Lynch, Independent Board Member at Ameriabank
- 14:09 • 21.04.21 'Mr. President, It Is Now in Your Power to Right Decades of Denial' - US Congressman Adam Schiff Urges Joe Biden to Recognize Armenian Genocide
- 12:37 • 03.04.21 Armenians of Nagorno-Karabakh in Despair After Trauma of Military Defeat - France 24
- 17:33 • 11.03.21 Interview with Kakhaber Kiknavelidze, an Independent Member of Ameriabank Board of Directors
- 17:57 • 26.01.21 Only Terrorists Keep Hostages, Putting Forward Preconditions for Their Release - Edmon Marukyan
- 13:33 • 22.01.21 Rep Adam Schiff Says Congress Should Recognize Artsakh
- 09:42 • 29.12.20 UN's Guterres Issues Global Appeal to Make 2021 'Year of Healing'
- 18:41 • 24.12.20 NASA's Mars 2020 Perseverance Rover Landing Animations
- 13:33 • 31.10.20 Azerbaijan Uses Prohibited Phosphorus Chemical Munitions - Defense Army Video
- 16:37 • 30.10.20 Artsakh Defense Army Units Neutralizing Azerbaijani Arms Supplies
- 11:25 • 28.10.20 Artsakh Defense Army Units Neutralizing Azerbaijani Drone
- 13:45 • 24.10.20 Nagorno-Karabakh's Status Has Been At the Heart of Our Approach - Zohrab Mnatsakanyan
- 11:51 • 24.10.20 Artsakh Defense Army Releases Video Featuring Damaged Azerbaijani Military Equipment
- 11:40 • 24.10.20 Artsakh Defense Army Units Inflicting Manpower Losses on Azerbaijan
- 10:39 • 24.10.20 Gas Pipeline Damaged in Azerbaijani Fire Targeting Nagorno-Karabakh's Capital
- 12:41 • 23.10.20 President Armen Sarkissian Meets Emmanuel Macron at Élysée Palace
- 12:16 • 23.10.20 Artsakh Defense Army Neutralizes Azerbaijani Military Hardware
- 12:02 • 22.10.20 Artsakh Defense Army Units Neutralizing Azerbaijani Military Infrastructures
- 10:35 • 22.10.20 President Armen Sarkissian Meets with NATO Secretary-General in Brussels
- 10:51 • 17.10.20 Buildings and Homes Lying in Ruins in Nagorno-Karabakh's Capital After Azerbaijani Shelling
- 15:09 • 15.10.20 Artsakh Defense Army's Precision Fire Gives Deadly Blow to Enemy
- 13:13 • 13.10.20 Artsakh Defense Army Units Destroying Azerbaijani Tank
- 12:56 • 12.10.20 Zohrab Mnatsakanyan: Ceasefire Does not Mandate Azerbaijan to Kill Civilians and Hit Civilian Settlements
- 12:23 • 12.10.20 Armenians Protest Outside Turkrish Embassy in Los Angeles
- 17:23 • 09.10.20 Losses in Azerbaijan's Military Featured in Defense Army Footage
- 15:53 • 09.10.20 Artsakh Defense Army Neutralizing Adversary's Transport Column
- 14:11 • 09.10.20 Turkey openly backs Azerbaijan 'far more aggressively than in the past' - ABC News on Syrian mercenaries fighting in Karabakh
- 15:52 • 08.10.20 Iconic Armenian Church Hit in Azerbaijani Attacks in Nagorno-Karabakh City (photos)
- 10:57 • 08.10.20 Artsakh Defense Army Continues High-Precision Strikes
- 14:24 • 07.10.20 War Situation in Karabakh on European Parliament's Agenda
- 19:31 • 05.10.20 Call for Urgent Action: Armenian Journalist Brings Intn'l Colleagues' Attention to Situation iin Artsakh After Azerbaijani Attacks
- 16:17 • 04.10.20 Turkey's Support to Syrian Mercenaries Fighting Against Artsakh: Facts About Azerbaijani Aggression
- 12:39 • 04.10.20 Nagorno-Karabakh's Capital Under Azerbaijani Strikes
- 13:49 • 03.10.20 Armenian Armed Forces Neutralize Azerbaijani Defense Positions
- 10:12 • 29.09.20 ArmenianTroops Destroy Azerbaijani Armored Fighting Vehicle on Frontline
- 23:42 • 28.09.20 There is a solid evidence that Azerbaijan has launched a thoroughly planned attack on the NKR
- 18:45 • 28.09.20 EU calls for Immediate End to Hostilities over Nagorno-Karabakh
Most popular articles Today Yesterday For a week
Economy
-
11:33 • 21.11.24 Unibank to Issue Subordinated Bonds for the First Time in Armenia
-
16:51 • 11.11.24 New features for Armeconombank’s Premium cardholders
Event
-
14:40 • 19.11.24 Ucom’s 5G network launched in 11 new cities
Science/tech
-
14:18 • 08.05.24 AstraZeneca withdrawing Covid vaccine worldwide