Malware In The Chrome Web Store
Google Chrome’s web store is the only place that users can (by default) get Apps and Extensions. Google stated that it’s confident in its ability to remove malware from the store and that by limiting users to it they’re helping to keep them safe.
As I predicted months ago the web store is being targeted by attackers. Naturally when a user sees an app or extension in the store they trust it more than they would one on some random website. Attackers take advantage of this to implant malicious extensions and apps into the browser.
A recent post by barracudanetworks provides information on a recent trend of apps claiming to be free versions of the ‘Angry Birds’ games. The apps request dangerous rights such as being able to access all data on all websites and their origin is very suspicious.
These apps have been downloaded nearly 100,000 times. The apps inject advertisements into webpages as a way to make money.
Barracudanetworks notes that this isn’t the first time it’s happened and they’ve seen other extensions do something similar.
Months ago I predicted this exact situation. Google needs to seriously step it up. They need to put out a new set of permissions (they’re currently working on a new set of refined permissions) and start vetting extensions that make use of dangerous ones.
blog comments powered by Disqus