!! A widely used browser extension, ModHeader,



 !! A widely used browser extension, ModHeader, has been removed from the Chrome Web Store after researchers found that its signed release contained a dormant capability to collect, encrypt, and potentially upload users' browsing-domain data.


The extension reportedly had about 1.6 million combined installations across Chrome and Microsoft Edge. ModHeader is a legitimate developer utility for modifying HTTP request and response headers.


Its broad permissions are expected for that function. However, they also give it the ability to interact with traffic and pages across all websites a user visits.


#cybersecuritynews

Comments

Popular posts from this blog

Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

Is Your Hosting Really Protecting You?