82 Chrome Extensions Found Selling User Data, 6.5 Million Users Affected
Overview
Research conducted by LayerX has uncovered that 82 Chrome extensions have been collecting and selling user data, impacting at least 6.5 million users. These extensions utilized disclosed but troubling practices to gather personal information, raising significant privacy concerns. Users of these extensions may have unknowingly compromised their data, which could lead to targeted advertising or other privacy invasions. The findings emphasize the need for users to be cautious about the permissions they grant to browser extensions and to regularly review their installed extensions. This incident serves as a stark reminder of the potential risks associated with seemingly innocuous tools that can operate within web browsers.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: 82 Chrome extensions
- Action Required: Users should review and remove any suspicious or unnecessary extensions from their browsers and be cautious about granting excessive permissions to new extensions.
- Timeline: Newly disclosed
Original Article Summary
LayerX research finds 82 Chrome extensions collecting and selling user data, affecting at least 6.5 million users through disclosed but concerning practices.
Impact
82 Chrome extensions
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
Users should review and remove any suspicious or unnecessary extensions from their browsers and be cautious about granting excessive permissions to new extensions.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Google.