News

Google Chrome Sync Feature Can Be Abused For Data Exfiltration

A Security Researcher Has Found A Malicious Chrome Extension In The Wild Abusing The Chrome Sync Process

Posted on

A cyber security researcher has discovered a malicious Google Chrome extension in the wild abusing the Chrome Sync process that can help hackers steal user data.

Threat actors have discovered they can abuse the Google Chrome sync feature to send commands to infected browsers and steal data from infected systems, bypassing traditional firewalls and other network defenses.

data exfiltration

Bojan Zdrnja, a Croatian security researcher, said on Thursday that during a recent incident response, he discovered that a malicious Chrome extension was abusing the Chrome sync feature as a way to communicate with a remote command and control (C&C) server and as a way to exfiltrate data from infected browsers.

Google Chrome

According to Zdrnja, the goal was to use the extension to "manipulate data in an internal web application that the victim had access to."

"While they also wanted to extend their access, they actually limited activities on this workstation to those related to web applications, which explains why they dropped only the malicious Chrome extension, and not any other binaries," Zdrnja said in the report.

"Now, malicious extensions are nothing new — there were a lot of analysis about such extensions and Google regularly removes dozens of them from Chrome Web Store, which is the place to go to in order to download extensions," the security researcher mentioned.

Comments

Related
Suggested
[   About Us  |  Terms of Use  |  Privacy Policy  |  Copyright  |  Cookies Policy  |  Hyperlink Policy  |  Disclaimer   ]
The website is owned and operated by the Newous Group.
Newous Group does not assume responsibility for the content of external sites.
The views expressed herein are solely ours.
Newous may receive commissions from retail offers.
© 2025 Newous. All rights reserved