Chrome, Firefox browser extensions leaked millions of users' data

Agencies
July 20, 2019

Popular browser extensions like ad blockers have been caught harvesting personal data of millions of consumers who use Chrome and Firefox -- not only their browsing histories but also exposing tax returns, medical records, credit card information and other sensitive data in the public domain.

According to an independent cyber security researcher Sam Jadali, the data has been leaked to a fee-based company called Nacho Analytics that gives unlimited access to any websites analytics data.

The data could be purchased for as little as $10 to $50, said Jadali whose report was first described in Ars Technica late on Friday.

"This non-stop flow of sensitive data over the past seven months has resulted in the publication of links to home and business surveillance videos hosted on Nest and other security services.

"Tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive, Intuit.com, and other online services" have been exposed, said the report.

The exposed data via eight browser extensions also include vehicle identification, numbers of recently bought automobiles, along with the names and addresses of the buyers.

Patient details, travel itineraries, Facebook Messenger attachments and Facebook photos, even private, are now available in the public domain.

Browser extensions - also known as plug-ins or add-ons - are apps that consumers can install to run alongside their browser for additional functionality.

The affected extensions were apps used by millions of people, including HoverZoom, SpeakIt!, and FairShare Unlock.

"The extensions have been remotely removed or disabled in consumers' browsers and are no longer available for download," said both Google and Firefox.

People who didn't download the extensions may also be affected.

"Nobody is immune to this. Even if you don't have any harmful extensions, the other people you interact with may have an extension on their computers that could be leaking the data you share with them," Jadali was quoted as saying.

Nacho Analytics, for example, promises to let people "see anyone's analytics account" and to provide "real-time web analytics for any website".

The company charges $49 per month, per domain, to monitor any of the top 5,000 most widely-trafficked websites.

The security expert has suggested users to delete all browser extensions they have installed in the past.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 10,2024

tokkottudeath.jpg

Mangaluru: A tragic accident took place on Saturday at Chembugudde near Thokkottu, claiming the life of a 47-year-old woman after a tanker lorry ran over her. The victim, identified as Rahmat H Rashid, was riding pillion with her husband, Abdul Rashid G, on their scooter. 

The couple was traveling from Yenepoya Hospital to Bajpe when the scooter skidded on the poorly maintained road. Rahmat fell onto the road and was fatally struck by a tanker lorry that was coming from behind. Despite being rushed to the hospital, doctors declared her dead upon arrival.

The incident prompted a swift response from the DYFI Ullal Taluk Committee, which staged a protest on Saturday night, condemning the unsafe condition of the road. Nithin Kuthar, president of the committee, criticized MLA and Legislative Assembly Speaker UT Khader for failing to ensure safe infrastructure, despite touting the road as toll-free. 

Kuthar demanded immediate repairs, warning that the committee would march to the MLA’s office with black flags if the road is not fixed within a week.

Former DYFI State President Sunil Kumar Bajal also voiced frustration over the deteriorating condition of Thokkottu market, highlighting the struggles people face while crossing roads riddled with dangerous potholes. In response to public outcry, temporary repairs were made to the road at Chembugudde on Sunday, though locals remain wary and demand a more permanent solution. 

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 12,2024

lebanon.jpg

The UN humanitarian coordinator for Lebanon has warned that the “picture of life in Lebanon remains grim,” highlighting an "alarming" level of human suffering and significant humanitarian consequences due to the ongoing Israeli carnage.

Imran Riza, the UN Deputy Special Coordinator and Resident and Humanitarian Coordinator for Lebanon (UNSCOL), provided a stark overview of the Arab country's dire circumstances in a statement released on Monday.

“The current picture of life in Lebanon remains grim. Yesterday, airstrikes reportedly killed 23 people, including seven children, in the village of Aalmat in Mount Lebanon,” Riza said on X.

An airstrike in the city of Tyre on the same day resulted in the tragic deaths of five siblings from a single family, all of whom had special needs, according to his statement.

He added that in the last week, Israeli airstrikes have killed at least 241 individuals and left 642 others injured in Lebanon, as reported by the Ministry of Health.

“In the past month, more than 185,000 people have fled their homes in their search for safety within the country, bringing the total to over 870,000 people internally displaced,” Riza said

The UN official highlighted that numerous individuals, including the elderly and those with health issues, are staying behind while witnessing the ruins of their ancestral homes.

He urged for the swift safeguarding of civilian people and infrastructure, emphasizing the necessity to uphold international humanitarian law and end the ongoing violence.

Lebanon’s National News Agency reported that Israeli forces bombed a house in the town of Maydoun in Bekaa on Monday night, killing three people and destroying the house.

Earlier, Israel bombed the northern town of Ain Yaaqoub, killing at least 14 people.

The killings came as Israeli military continued to pound Lebanon, bombing shops selling electrical appliances in the southern city of Tyre and carrying out air raids on the towns of Shamshtar in eastern Baalbek and Roumine in southern Nabatieh.

Lebanon’s Ministry of Health said Israeli attacks killed at least 54 people across the country on Monday.

Israel’s merciless attacks continue despite calls from the UN Security Council for an immediate ceasefire and directives from the International Court of Justice urging measures to prevent genocide and alleviate the dire humanitarian situation in Gaza and Lebanon.

In Lebanon, at least 3,243 people have been killed and 14,134 others wounded in Israeli attacks since the war on Gaza began on October 7, 2023.

The Lebanese resistance movement Hezbollah opened a support front for Palestinians in Gaza only a day after the Israeli regime unleashed its genocidal war on the besieged territory.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
November 14,2024

srirang.jpg

Bengaluru: The Prime Minister Narendra Modi led union government has requested the Karnataka High Court to direct the Mandya district administration and the state government to clear a madrasa operating within the premises of the historic Jama Masjid in Srirangapatna.

The Waqf Board, opposing this move, has claimed the mosque as its property and defended the right to conduct madrasa activities there.

The matter was brought before a division bench headed by Chief Justice N V Anjaria following a public interest litigation filed by a person named Abhishek Gowda from Kabbalu village in Kanakapura taluk. The petition alleged “unauthorised madrasa activities” within the mosque.

Representing the Central government, Additional Solicitor General of India for High Court of Karnataka, K Arvind Kamath argued that the Jama Masjid was designated as a protected monument in 1951, yet unauthorised madrasa operations continue there.

He noted that concerns over potential law and order issues have so far prevented any intervention. Kamath urged the court to direct the Mandya district administration to take action and vacate the madrasa from the mosque.

In defence, lawyers for the state government and the Waqf Board contested this request, stating that the Waqf Board had been recognised as the owner of the property since 1963 and, thus, conducting madrasa activities there is lawful.

After hearing both sides, the bench adjourned the case for further arguments, scheduling the next hearing for November 20.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.