Polymorphic Extensions Can Steal Your Crypto and Passwords

in news •  last month 

Once installed, it can disable existing extension and impersonate it to steal your data. This is allowed by Chrome permissions. A legitimate extension can be bought and updated to perform this attack.

Making extensions only available "On Click", checking and managing permissions along with browser isolation can help to mitigate this risk to a significant extent. It is best to minimize usage of Extensions. Brave wallet is likely safe (I'm not an expert).

SquareX's Report

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!