Get the latest tech news

Chrome and Edge browser extensions secretly hijacked, spied on millions of users | Some even received "Verified" and "Featured" badges from Google and Microsoft


According to researchers at Koi Security, the malicious extensions were part of a coordinated operation involving at least 18 known add-ons listed on the Chrome and Edge...

Many of these malicious add-ons remained available on the Chrome and Edge web stores for years, with some even receiving the coveted "Featured" and "Verified" badges, raising serious questions about the extension review processes used by Google and Microsoft. Describing the extension as a "carefully crafted Trojan horse," Koi Security analyst Idan Dardikman noted that this was not the work of amateur scammers, but rather a sophisticated operation orchestrated by individuals who clearly knew what they were doing. Other malicious extensions in the campaign include various emoji keyboards, weather forecast tools, video speed controllers, VPN proxies for Discord and TikTok, dark theme enablers, volume boosters, and YouTube unblockers.

Get the Android app

Or read this on r/technology

Read more on:

Photo of Google

Google

Photo of Microsoft

Microsoft

Photo of Edge

Edge

Related news:

News photo

Google Hires Top A.I. Leaders From Windsurf, Which OpenAI Was Courting

News photo

The verdict is in: Millions of dollars in Tesla EV rebate claims were legitimate, Ottawa says

News photo

Windsurf’s CEO goes to Google; OpenAI’s acquisition falls apart