Chrome, Firefox browser extensions leaked millions of users' data

Agencies
July 20, 2019

Popular browser extensions like ad blockers have been caught harvesting personal data of millions of consumers who use Chrome and Firefox -- not only their browsing histories but also exposing tax returns, medical records, credit card information and other sensitive data in the public domain.

According to an independent cyber security researcher Sam Jadali, the data has been leaked to a fee-based company called Nacho Analytics that gives unlimited access to any websites analytics data.

The data could be purchased for as little as $10 to $50, said Jadali whose report was first described in Ars Technica late on Friday.

"This non-stop flow of sensitive data over the past seven months has resulted in the publication of links to home and business surveillance videos hosted on Nest and other security services.

"Tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive, Intuit.com, and other online services" have been exposed, said the report.

The exposed data via eight browser extensions also include vehicle identification, numbers of recently bought automobiles, along with the names and addresses of the buyers.

Patient details, travel itineraries, Facebook Messenger attachments and Facebook photos, even private, are now available in the public domain.

Browser extensions - also known as plug-ins or add-ons - are apps that consumers can install to run alongside their browser for additional functionality.

The affected extensions were apps used by millions of people, including HoverZoom, SpeakIt!, and FairShare Unlock.

"The extensions have been remotely removed or disabled in consumers' browsers and are no longer available for download," said both Google and Firefox.

People who didn't download the extensions may also be affected.

"Nobody is immune to this. Even if you don't have any harmful extensions, the other people you interact with may have an extension on their computers that could be leaking the data you share with them," Jadali was quoted as saying.

Nacho Analytics, for example, promises to let people "see anyone's analytics account" and to provide "real-time web analytics for any website".

The company charges $49 per month, per domain, to monitor any of the top 5,000 most widely-trafficked websites.

The security expert has suggested users to delete all browser extensions they have installed in the past.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 13,2024

lebenonstrikes.jpg

Beirut: The Israeli army on Tuesday continued to launch attacks against civilians in Lebanon, targeting them in several areas without prior evacuation warnings.

However, 13 airstrikes on Beirut’s southern suburbs in the space of only three hours were preceded by evacuation warnings.

The attacks caused no injuries but resulted in widespread destruction of residential buildings and commercial, medical and educational centers.

The airstrikes in southern Lebanon and Bekaa region, reaching Akkar in Lebanon’s far north, erased any hope of a near-term ceasefire settlement.

The strikes were accompanied by an announcement on Israel’s Channel 14 that “the Israeli army has expanded its operations in southern Lebanon to areas it had not reached since the beginning of the ground operation.”

About 50 days have passed since Israel intensified its hostile operations in Lebanon targeting Hezbollah. The death toll from these confrontations and attacks has passed 3,200, with more than 14,000 wounded.

For the first time, an airstrike targeted a mountainous area between Baalchmay and Aabadiyeh on the road leading to Aley, destroying a building housing displaced people.

The mayor of Baalchmay, Adham Al-Danaf, confirmed that “the airstrike targeted a residential building in the Dhour Aabadiyeh area.”

The initial toll from the Ministry of Health showed “five people killed and two injured.”

The raids that targeted Beirut’s southern suburbs for the first time in the morning, unlike nightly raids before, caused huge destruction. Those who evacuated their homes after Israeli warnings, used their phones to record the collapse of empty buildings in Sfeir, Haret Hreik, Bir Al-Abed, Mrayjeh, Laylaki and Hadath.

Israeli warplanes also targeted Tyre, where a strike on a building killed three people and injured many others, while a raid on Tefahta killed a man identified as Kifah Khalil and his family.

Attacks were widespread, with Yater and Zebqine subject to artillery shelling, a civilian being killed in Hermel, and further attacks on Bouday and an area between the towns of Srifa and Arsoun.

A raid on the town of Siddiqin killed two people and injured several others, while an attack on the Mechref farm led to one fatality and multiple injuries.

The search for those missing after an Israeli raid on the town of Ain Yaacoub in Akkar, in the northernmost part of Lebanon, continued until dawn.

During the operation, 14 bodies were retrieved, identified as those of residents displaced from the town of Arabsalim in the Iqlim Al-Tuffah area of the south, along with members of a Syrian family, a mother and three of her children. Additionally, there were 10 people in critical condition.

The targeted residence belongs to a Lebanese citizen, Hussein Hashim, who is reported to be a member of the Syrian Social Nationalist Party.

An airstrike on the town of Saksakiyeh in the Sidon region on Monday night resulted in yet another tragedy.

It appeared that the intended target was the Shoumer family, who just days before lost Hussein Amin Shoumer and his two sisters in a drone strike near Al-Awali River.

Israeli army spokesperson Avichay Adraee issued additional evacuation warnings for towns in the southern region along the Litani River, which, according to estimates from the mayors, are currently 90 percent uninhabited.

In the meantime, Hezbollah announced its continued efforts to “combat the intrusions of Israeli forces and to strike military installations and towns in the north.”

Hezbollah said in a statement that it confronted “an Israeli Hermes 450 drone in the airspace of Nabatieh and forced it to leave Lebanese airspace.”

The party also announced that it targeted “Kfar Blum settlement with a rocket salvo.”

On the Israeli side, air raid sirens sounded in areas of Upper and Western Galilee and in the town of Kiryat Shmona and its surroundings.

The Israeli army confirmed that “a drone exploded in Nesher, east of Haifa, without activating the air raid sirens,” and that “a drone launched from Lebanon crashed into a school in Gesher HaZiv, north of Nahariya.”

Israel’s Channel 13 reported the Israeli military’s assessment regarding Hezbollah’s military strength, claiming that the group currently possesses approximately 100 precision missiles, thousands of artillery shells, and hundreds of rockets. Additionally, it was highlighted that “there are around 200 Lebanese towns that remain unvisited.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.