Security experts find millions of users running malware infected extensions from Google Chrome Web Store

security experts find millions of users running malware infected extensions from google chrome web store

Number of users with a benign, malware-containing, policy-violating, or vulnerable extension installed–The blue tick denotes the means and the red line the median Credit: arXiv (2024). DOI: 10.48550/arxiv.2406.12710

A trio of security experts at Stanford University has found that millions of people are running an infected version of Chrome web browser due to extensions installed from the Google Chrome Web Store (GCWS). Sheryl Hsu, Manda Tran and Aurore Fass have posted a paper to the arXiv preprint server describing their findings after studying thousands of extensions on GCWS.

To get the most out of web browsers, such as Google's Chrome, users download extensions from popular extension sites. One of the most popular and well-known such sites is GCWS—it hosts extensions for the Chrome web browser that have been written by third-party programmers.

Two of the main problems with downloading and using extensions written by third parties is the uneven level of quality and the possibility of malware. In this new effort, the researchers have looked at the latter issue, and the scale of risk for people using extensions downloaded from GCWS.

The researchers took two approaches to determine how many of the thousands of extensions hosted on GCWS have what they describe as security-noteworthy extensions (SNEs)—those that violate GCWS policy or contain malware or vulnerable code.

The first involved analyzing data from past research efforts into security issues with Chrome web extensions. The second involved downloading all extensions (approximately 125,000) that were available on the site between July 2020 and February 2023 and then analyzing the code that was used when they were written, looking for telltale signs of malware infection.

They also analyzed the site's download history and the longevity of extensions on the site.

The research team found that approximately 346 million users had downloaded a SNE from GCWS during the two-year period under study—280 million of which involved SNEs with malware. They note that Google claims that less than 1% of extensions hosted by the store have malware—the company also claims to vet all extensions hosted on the site.

The researchers also found that SNEs differ widely in how long they are available on GCWS, from months to years, and that users very seldom report an extension as being problematic.

More information: Sheryl Hsu et al, What is in the Chrome Web Store? Investigating Security-Noteworthy Browser Extensions, arXiv (2024). DOI: 10.48550/arxiv.2406.12710

© 2024 Science X Network

This story was originally published on Tech Xplore. Subscribe to our newsletter for the latest sci-tech news updates.

OTHER NEWS

12 minutes ago

‘I was blown away’: Pink’s touching tribute to daughter after major announcement

14 minutes ago

House That! Ben Wyatt moving on from Nedlands mansion only a couple of years after buying it for $3.69m

17 minutes ago

The Riven remake transforms a tricky classic into a modern masterpiece

17 minutes ago

Project Orion Needs to Expand on Cyberpunk 2077's Romance Options

17 minutes ago

Blackhawks take defenceman Artyom Levshunov second overall at 2024 NHL Draft

17 minutes ago

Where To Find Elden Ring: Shadow Of The Erdtree's Two-Headed Turtle Talisman

17 minutes ago

Garda charged with leaking personal data of 14 people from PULSE to man charged with a drug trafficking offence

17 minutes ago

Dagestani Jews look to rebuild after extremist attacks in the restive region of southern Russia

17 minutes ago

Chicago Sky Fans Outraged After Fan Favorite Kysre Gondrezick Gets Released

17 minutes ago

Rishi Sunak jokes with apprentice during Teesside campaign visit

17 minutes ago

Parking meters to go completely cashless in one busy CBD

17 minutes ago

FREDA LEWIS-STEMPEL did a 1,000 mile road trip in the new Tesla Model 3 using only green energy - is range anxiety over?

20 minutes ago

D'Angelo Russell plans to exercise options, return to Lakers

23 minutes ago

Oil prices pare gains amid hopes US will cut interest rates

23 minutes ago

Italy have no alternative but to improve at Euros: coach Spalletti

23 minutes ago

Frustration over dithering on new Cabinet announcement

23 minutes ago

Video: Stephen A. Smith appearance on NewsNation during Biden-Trump debate coverage leaves viewers stunned: 'This man is everywhere!'

23 minutes ago

Video: Simone Biles seizes lead on Day 1 of US Olympic Trials ahead of Jordan Chiles and Sunisa Lee despite wobbly fifth-place performance on balance beam

30 minutes ago

‘We went into our shells’: Goodwin admits Demons played it too safe in goalless final term

30 minutes ago

'I teach women how to dress in a 'flattering' way for their body shape. It's not a dirty word.'

30 minutes ago

Opinion: Capitals' Recent Trades Look More Like Unnecessary Gambles Than Needle-Movers

30 minutes ago

Israel's Bombs Flatten Lebanese Village After Months Of Air Strikes | N18G | CNBC TV18

30 minutes ago

At UK's Glastonbury festival: music, sunshine and a call to vote

30 minutes ago

Rickie Fowler aims for repeat success as PGA stars like Scottie Scheffler absent

30 minutes ago

‘Holiday mentality’ leaves people spending £250 more on extras while away

30 minutes ago

Toys"R"Us AI-generated advert by Toys”R”Us panned for including implausible scenes

30 minutes ago

Elvis' Graceland mansion attempted foreclosure under federal investigation: report

30 minutes ago

Warren Buffett donates record $5.3 billion Berkshire shares to charity

30 minutes ago

Not a government decision to award ex-special forces soldier Ben Roberts-Smith, Anthony Albanese says

33 minutes ago

As North Korean and Chinese threats rise, US looks to lock in defense partnerships with Asian allies

35 minutes ago

Judge denies Alec Baldwin's motion to dismiss manslaughter charges in ‘Rust' shooting

36 minutes ago

Sharks Celebrate As Macklin Celebrini Is Officially Drafted No. 1

36 minutes ago

Rangers Draft EJ Emery With First Round Pick

36 minutes ago

‘I was pretty rattled by the last injury’: Trbojevic accepts shift to centres for Manly return

36 minutes ago

Hurdler Lolo Jones returns to Olympic trials at 41, advances to semis on sore hamstring

36 minutes ago

Got the holiday blues? See T-Rex bones, cuddle a cat or smash stuff

36 minutes ago

Will FY25 be kinder to Core Lithium shares?

36 minutes ago

The effort to bring back affirmative action is dead in California

36 minutes ago

Better Know a B1G: Adv. Stat Comparison Northwestern Wildcats

36 minutes ago

Humana-Paredes, Wilkerson team up in Paris as part of Olympic beach volleyball team