🖥️較早收集於 52h

3700 萬 Chrome 擴充套件外洩瀏覽紀錄

3700 萬 Chrome 擴充套件外洩瀏覽紀錄
PostLinkedIn
🖥️閱讀原文: Computerworld

💡Popular AI tools like Knowee leak your history—check your extensions now

⚡ 30-Second TL;DR

有什麼變化

3700 萬安裝的 287 擴充套件外洩 URL 至資料經紀商

為什麼重要

擁有 3700 萬安裝的 287 個 Chrome 擴充套件將瀏覽紀錄傳至外部伺服器,包括 VPN 與如 Knowee AI 的生產力工具。研究者 Q Continuum 透過自動化分析偵測 URL 外洩。資料外洩使用 AES-256 等加密,帶來企業間諜風險。

下一步行動

Audit installed Chrome extensions for broad permissions using chrome://extensions/.

誰應關注:Enterprise & Security Teams

關鍵要點

  • 3700 萬安裝的 287 擴充套件外洩 URL 至資料經紀商
  • 包含 Knowee AI、Similarweb 與生產力工具
  • 使用 base64、ROT47、AES-256 加密混淆
  • 帶來企業間諜與憑證竊取風險

🧠 深度解析

背景與延伸:來自公開資料,非原文內容。引用 6 個來源。

🔑 增強重點摘要

  • 287 Chrome extensions with 37.4 million combined installations were found exfiltrating browsing history data to over 30 companies, with approximately 20 million installations sending data to unknown entities[1]
  • 153 of the confirmed data-leaking extensions began transmitting browsing history immediately after installation, accounting for 27.2 million installs alone[2]
  • Data collection involves 32 separate publishing entities with suspected coordinated infrastructure overlapping with known spyware distribution networks, indicating a centralized data broker operation rather than independent rogue developers[2]
  • Outbound data payloads use sophisticated obfuscation techniques including base64, ROT47, LZ-String compression, and AES-256 encryption wrapped in RSA-OAEP to evade detection[4]
  • Affected extensions span multiple categories including VPNs, productivity tools, coupon finders, PDF utilities, and browser utilities—many with hundreds of thousands to millions of users—creating widespread exposure to corporate espionage and credential harvesting risks[3][4]

🛠️ 技術深入

• Researcher Q Continuum built an automated testing pipeline that launched Chrome instances, installed extensions, visited predefined websites, and captured outbound communications to identify data exfiltration patterns • Encrypted payloads were decoded to reveal raw Google search URLs, page referrers, user IDs, and timestamps being transmitted to proprietary domains and cloud-provider endpoints[4] • Extensions requested broad host permissions (cross-website access) enabling comprehensive browsing history collection[3] • Data collection infrastructure includes companies such as Similarweb, Big Star Labs (identified as a Similarweb subsidiary), Semrush, Alibaba Group, and ByteDance[1] • Similarweb's February 27, 2025 financial filing confirmed the company's reliance on data gathered from browser extensions and apps distributed through Chrome Web Store, Google Play, and Apple App Store[1] • A related cluster of 30 malicious extensions with over 260,000 installs employed advanced manipulation techniques including hidden iframe injection, real-time browser UI manipulation, tracking pixels, session data exfiltration, webpage content replacement, phishing overlays, and silent user redirection[2]

🔮 前景展望AI analysis grounded in cited sources

This discovery underscores critical vulnerabilities in the browser extension ecosystem and highlights the urgent need for enhanced security governance within app stores. The coordinated nature of the operation—involving 32 publishing entities and centralized data broker infrastructure—suggests that extension-based surveillance has become a systematic, profitable business model. Organizations face elevated risks of corporate espionage through employee browsing data exposure, while individual users confront privacy erosion and credential harvesting threats. The incident may accelerate regulatory scrutiny of extension permissions, data collection practices, and app store vetting procedures. Additionally, the sophisticated obfuscation techniques employed (AES-256 encryption, RSA-OAEP wrapping) indicate that malicious actors are investing in advanced evasion methods, potentially outpacing detection capabilities.

時間線

2025-06
Ox Security researchers began attempting to disclose vulnerabilities in popular VSCode extensions, with no maintainer response received
2025-02
Similarweb filed financial disclosure attesting to reliance on data from browser extensions and third-party app stores
2026-02
Security researcher Q Continuum published findings identifying 287 Chrome extensions leaking browsing data to 30+ companies across 37.4 million installations
📰

AI 週報

閱讀本週精選 AI 大事摘要 →

👉相關動態

AI 策展新聞聚合。所有內容版權歸原始發布者所有。
原始來源: Computerworld

這是摘要,不是原文。去看原站,或訂閱每週簡報。

每週 AI 簡報

每週一封,可隨時退訂。