Be cautious while installing Google Chrome extensions: Cyber security agency CERT-In

Computer Emergency Response Team of India, the national technology arm to combat cyber attacks and guard the Indian cyber space, said it has also been found that these extensions contained code to bypass Google Chrome’s web store security scans

July 01, 2020 02:10 pm | Updated 02:59 pm IST - New Delhi

The agency advised Internet users to only install extensions that are absolutely needed and refer user reviews before doing so

The agency advised Internet users to only install extensions that are absolutely needed and refer user reviews before doing so

(Subscribe to our Today's Cache newsletter for a quick snapshot of top 5 tech stories. Click here to subscribe for free.)

Internet users should exercise caution while installing Google Chrome extensions as the company has removed over 100 malicious links after they were found collecting “sensitive” user data, country’s cyber security agency said on Wednesday.

The Computer Emergency Response Team of India (CERT-In), the national technology arm to combat cyber attacks and guard the Indian cyber space, said it has also been found that these extensions contained code to bypass Google Chrome’s web store security scans.

The malicious extensions had the ability to take screenshots, read the clipboard, harvest authentication cookies or grab user keystrokes to read passwords and other confidential information, it said.

“It has been reported that Google has removed 106 extensions of the Google Chrome browser from the chrome web store which were found collecting sensitive user data,” the agency said in the advisory.

“These extensions, reportedly posed as tools to improve web searches, convert files between different formats as security scanners and more,” it added.

The federal cyber security agency suggested users to uninstall Google Chrome extensions with IDs given in the IOCs (organisational chart) section.

Users can visit the chrome extensions page and subsequently enable developer mode to see if they have installed any of the malicious extensions and then remove them from their browsers, it said.

The agency advised Internet users to only install extensions that are absolutely needed and refer user reviews before doing so.

They should uninstall extensions which are not in use, it said, adding that users should not install extensions from unverified sources.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.