Chrome, Firefox browser extensions leaked millions of users' data

Agencies
July 20, 2019

Popular browser extensions like ad blockers have been caught harvesting personal data of millions of consumers who use Chrome and Firefox -- not only their browsing histories but also exposing tax returns, medical records, credit card information and other sensitive data in the public domain.

According to an independent cyber security researcher Sam Jadali, the data has been leaked to a fee-based company called Nacho Analytics that gives unlimited access to any websites analytics data.

The data could be purchased for as little as $10 to $50, said Jadali whose report was first described in Ars Technica late on Friday.

"This non-stop flow of sensitive data over the past seven months has resulted in the publication of links to home and business surveillance videos hosted on Nest and other security services.

"Tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive, Intuit.com, and other online services" have been exposed, said the report.

The exposed data via eight browser extensions also include vehicle identification, numbers of recently bought automobiles, along with the names and addresses of the buyers.

Patient details, travel itineraries, Facebook Messenger attachments and Facebook photos, even private, are now available in the public domain.

Browser extensions - also known as plug-ins or add-ons - are apps that consumers can install to run alongside their browser for additional functionality.

The affected extensions were apps used by millions of people, including HoverZoom, SpeakIt!, and FairShare Unlock.

"The extensions have been remotely removed or disabled in consumers' browsers and are no longer available for download," said both Google and Firefox.

People who didn't download the extensions may also be affected.

"Nobody is immune to this. Even if you don't have any harmful extensions, the other people you interact with may have an extension on their computers that could be leaking the data you share with them," Jadali was quoted as saying.

Nacho Analytics, for example, promises to let people "see anyone's analytics account" and to provide "real-time web analytics for any website".

The company charges $49 per month, per domain, to monitor any of the top 5,000 most widely-trafficked websites.

The security expert has suggested users to delete all browser extensions they have installed in the past.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 11,2024

Udupi, Nov 11: A traveller reportedly lost ₹4.1 lakh after attempting to book a cab online in Udupi. 

At around 1:30 PM on November 7, the man from West Bengal searched for car rentals on Google and selected a website named "Shakti Car Rentals." Shortly after, he was contacted by someone claiming to be "Rohit Sharma," who directed him to pay a registration fee of ₹150 on the site.

After unsuccessful payment attempts via both his Canara Bank debit card and SBI credit card (without receiving an OTP), "Rohit Sharma" instructed him to pay the driver directly. But at 1:47 PM, he received messages showing deductions of ₹3.3 lakh from his SBI credit card and ₹80,056 from his Canara Bank debit card, totaling ₹4.1 lakh.

The complainant alleges fraud through a deceptive link disguised as a booking token fee. A case has been registered at Udupi Town Police Station.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 11,2024

Mangaluru: Six youths including teenagers have been arrested by the Bantwal Rural Police in connection with a brutal assault on 21-year-old Aboobakar (name changed to hide identity), an incident that was widely shared on social media after footage revealed the victim tied to a pole and violently beaten.

The arrested individuals, all from Kanchinadkapadavu, Sajipanadu village in Ullal Taluk, have been identified as Mohammad Sapwan (25), Mohammad Rizwan (25), Irfan (27), Anis Ahmad (19), Nasir (27), and Shakeer (18). According to police reports, the assault took place on November 7 in Kanchinadkapadavu.

The sequence of events began when Aboobakar was reportedly called to a residence in Kanchinadkapadavu by a female relative. Upon his arrival, he was confronted by the accused, who questioned his presence, tied him to a pole with ropes, and attacked him while he was shirtless. 

Aboobakar managed to file a police complaint the following day, detailing the assault. As his injuries worsened, he was admitted to a private hospital in Mangaluru.

While in the hospital, Aboobakar alleged that his attackers intended to kill him during the assault. This statement led to additional charges of attempted murder being filed. 

Police officials stated that the suspects were subsequently apprehended, charged with group assault and attempted murder, and placed in judicial custody. The investigation is ongoing, and further details are awaited.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 17,2024

hizbullah.jpg

An Israeli airstrike on the office of Syria’s Baath party in Lebanon’s capital Beirut has killed the Lebanese resistance movement Hezbollah's Media Relations Officer, Mohammad Afif, reports say.

Lebanon's National News Agency (NNA) reported that the Israeli raid struck the Ba'ath party’s building in central Beirut district of Ras Al-Naba'a on Sunday, adding that the strike was an attempt to assassinate the leader of the resistance media front.

According to Baath Secretary-General Ali Hijazi, Afif was having a meeting in the Baath Party headquarters when Israel carried out the attack.

"Afif did not fight with weapons and did not lead a military unit in Hezbollah. Rather, he led a media unit," he said.

Reuters, Sky News, Al Jazeera and a number of Henrew-language media reported that Afif was killed in the Israeli strike.

However, Hezbollah has not yet confirmed Afif’s death or whether he was present at the site or not.

Earlier, the Lebanese Health Ministry said at least one person was killed and three others injured after an Israeli strike targeted a central district in Beirut.

Lebanon's al-Mayadeen television network reported that five people were killed in the attack.

The latest development came after Afif said Hezbollah was behind the Caesarea operation and targeting Netanyahu’s home during a speech at the Ghobeiry area in the southern suburbs of Beirut on October 22.

This was the second assassination attempt on Afif in the last two months, after he survived an attack on the Hezbollah media relations office several weeks ago.

Israel launched a ground assault and massive air campaign against Lebanon in late September after a year of exchanging fire across the Lebanese border in parallel with the Gaza war.

At least 3,287 people have been killed in Israeli strikes in Lebanon over the past year, with the vast majority in the past seven weeks. Another 14,222 have been wounded, mostly women and children.

In response to the ongoing aggression, the Lebanese resistance movement Hezbollah has been staging hundreds of retaliatory strikes against the occupied Palestinian territories and the Israeli forces trying to advance on southern Lebanese areas.

The movement has vowed to sustain its strikes until the regime ends the escalation.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.