Tuesday, March 17, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Press Release GlobeNewswire

Millions of Enterprises at Risk: SquareX Shows How Malicious Extensions Bypass Google’s MV3 Restrictions

October 3, 2024
in GlobeNewswire
Reading Time: 6 mins read
5
SHARES
251
VIEWS
Share on TwitterShare on LinkedInShare on Facebook

SINGAPORE, Oct. 03, 2024 (GLOBE NEWSWIRE) —

At DEF CON 32, the SquareX research team delivered a hard-hitting presentation titled Sneaky Extensions: The MV3 Escape Artists where they shared their findings on how malicious browser extensions are bypassing Google’s latest standard for building chrome extensions: Manifest V3 (MV3)’s security features, putting millions of users and businesses at risk.

SquareX’s research team publicly demonstrated rogue extensions built on MV3. The key findings include:

  • Extensions can steal live video streams, such as those from Google Meet and Zoom Web, without requiring special permissions.
  • The rogue extensions can act on a user’s behalf to add collaborators to private GitHub repositories.
  • The extensions are capable of hooking into login events to redirect users to a page disguised as a password manager login.
  • Extensions built on MV3 can steal site cookies, browsing history, bookmarks, and download history with ease, like their MV2 counterparts.
  • The rogue extensions can add pop-ups to the active webpage, such as fake software update prompts, tricking users into downloading malware.

Browser extensions have long been a target for malicious actors — a Stanford University report estimates that 280 million malicious Chrome extensions were installed in recent years. Google has struggled to address this issue, often relying on independent researchers to identify malicious extensions. In some cases, Google has had to manually remove them, such as the 32 extensions taken down in June last year. By the time they were removed, these extensions had already been installed 75 million times.

Most of these issues arose because the Chrome extension standard, Manifest Version 2 (MV2), was riddled with loopholes that granted extensions excessive permissions, and allowed scripts to be injected on the fly, often without users’ knowledge. This allowed malicious actors to easily exploit these vulnerabilities to steal data, inject malware, and access sensitive information. MV3 was introduced to address these problems by tightening security, limiting permissions, and requiring extensions to declare their scripts beforehand. 

However, SquareX’s research shows that MV3 falls short in many critical areas, demonstrating how attackers are still able to exploit minimal permissions to carry out malicious activity. Both individual users and enterprises are exposed, even under the newer MV3 framework.

Today’s security solutions, such as endpoint security, SASE/SSE, and Secure Web Gateways (SWG), lack visibility into installed browser extensions. There is currently no mature tool or platform capable of dynamically instrumenting these extensions, leaving enterprises without the ability to accurately assess whether an extension is safe or malicious. 

SquareX is committed to the highest level of cybersecurity protection for enterprises and has built key innovative features to solve this problem, which include;

  • Fine grained policies to decide which extensions to allow / block and parameters include extension permissions, creation date, last update, reviews, ratings, user count, author attributes etc
  • SquareX blocks network requests sent by extensions at run time – based on policies, heuristics and machine learning insights
  • SquareX is also experimenting with dynamic analysis of Chrome Extensions using a modified Chromium browser in its cloud server

These are part of SquareX’s Browser Detection and Response solution which is being deployed at medium-large enterprises and is effectively blocking these attacks.

Vivek Ramachandran, Founder & CEO of SquareX, warned about the mounting risks: “Browser extensions are a blind spot for EDR/XDR and SWGs have no way to infer their presence. This has made browser extensions a very effective and potent technique to silently be installed and monitor enterprise users, and attackers are leveraging them to monitor communication over web calls, act on the victim’s behalf to give permissions to external parties, steal cookies and other site data and so on.” “Our research proves that without dynamic analysis and the ability for enterprises to apply stringent policies, it will not be possible to identify and block these attacks. Google MV3, though well intended, is still far away from enforcing security at both a design and implementation phase,” said Vivek Ramachandran.

About SquareX
SquareX helps organizations detect, mitigate and threat-hunt client-side web attacks happening against their users in real time.

SquareX’s industry-first Browser Detection and Response (BDR) solution, takes an attack-focused approach to browser security, ensuring enterprise users are protected against advanced threats like malicious QR Codes, Browser-in-the-Browser phishing, macro-based malware, malicious extensions and other web attacks encompassing malicious files, websites, scripts, and compromised networks.

With SquareX, enterprises can also provide contractors and remote workers with secure access to internal applications, enterprise SaaS, and convert the browsers on BYOD / unmanaged devices into trusted browsing sessions.

Contact

Head of PR
Junice Liew
SquareX
junice@sqrx.com

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.
ShareTweet1ShareSendShare2
Previous Post

Justin Morrison Joins Arctiq as Vice President of Sales, West Region

Next Post

3D Design Software Market: Comprehensive study explores Huge Growth in Future

Related Posts

EXL advances EXLerate.ai agentic AI platform to support enterprise-scale adoption with NVIDIA technologies

NEW YORK, March 16, 2026 (GLOBE NEWSWIRE) -- EXL , a global data and AI company, announced that its agentic AI platform, EXLerate.ai™, is now supported by NVIDIA AI Enterprise, strengthening the companies’ collaboration to deliver enterprise AI solutions for regulated industries. EXL offers an extensive suite of agentic AI capabilities...

Read moreDetails

Top Seller Cassaundra0328 Announces Exclusive Live Auction Event on Whatnot

Wake Forest, NC, March 16, 2026 (GLOBE NEWSWIRE) -- Tomorrow, March 17, vintage decor enthusiasts and deal-seekers have a front-row seat to the future of retail. Renowned seller Cassaundra0328 is thrilled to announce a high-energy, live auction event on Whatnot, the leading social commerce platform. The Main Event: Vintage Finds...

Read moreDetails

BGIN BLOCKCHAIN LIMITED Announces Successful Tape-Out of 4nm BT1 Bitcoin Mining Chip

SINGAPORE, March 17, 2026 (GLOBE NEWSWIRE) -- BGIN BLOCKCHAIN LIMITED (“BGIN” or the “Company”; NASDAQ: BGIN), a digital asset technology company with proprietary cryptocurrency mining technologies and a manufacturer of cryptocurrency mining hardware, today announced first-pass silicon success in the 4nm BT1 Bitcoin mining ASIC chip—the Company's first proprietary chip...

Read moreDetails

STMicroelectronics and Leopard Imaging accelerate robotics vision with NVIDIA Jetson-ready multi-sensor module

 STMicroelectronics and Leopard Imaging accelerate robotics vision with NVIDIA Jetson-ready multi-sensor module Multimodal module combining 2D imaging, 3D depth sensing, and human-like motion perception  NVIDIA Holoscan Sensor Bridge ensuring multi-gigabit plug and play connectivity with Jetson platforms Fully supported by NVIDIA Isaac open robot development platform Geneva, March 16, 2026...

Read moreDetails

STMicroelectronics and Leopard Imaging accelerate robotics vision with NVIDIA Jetson-ready multi-sensor module

 STMicroelectronics and Leopard Imaging accelerate robotics vision with NVIDIA Jetson-ready multi-sensor module Multimodal module combining 2D imaging, 3D depth sensing, and human-like motion perception  NVIDIA Holoscan Sensor Bridge ensuring multi-gigabit plug and play connectivity with Jetson platforms Fully supported by NVIDIA Isaac open robot development platform Geneva, March 16, 2026...

Read moreDetails

Decisiv and Besson Management Group Form Strategic Partnership

Reston, Virginia, March 16, 2026 (GLOBE NEWSWIRE) -- Reston, Virginia – March 16, 2026 – Decisiv, Inc., the industry leader in Service Relationship Management (SRM) solutions, announced today an agreement with Besson Management Group, Inc. (BMG) to integrate and resell  TRITECH's Expert Technician Support, a subscription-based technical support service that provides expert diagnostic and troubleshooting assistance for...

Read moreDetails

Decisiv and Besson Management Group Form Strategic Partnership

Reston, Virginia, March 16, 2026 (GLOBE NEWSWIRE) -- Reston, Virginia – March 16, 2026 – Decisiv, Inc., the industry leader in Service Relationship Management (SRM) solutions, announced today an agreement with Besson Management Group, Inc. (BMG) to integrate and resell  TRITECH's Expert Technician Support, a subscription-based technical support service that provides expert diagnostic and troubleshooting assistance for...

Read moreDetails

Micron in High-Volume Production of HBM4 Designed for NVIDIA Vera Rubin, PCIe Gen6 SSD and SOCAMM2

News highlights: HBM4 36GB 12H in high-volume production, designed for NVIDIA® Vera Rubin — greater than 2.8 TB/s1 and with 20% better power efficiency2 Industry's first PCIe® Gen6 SSD in high-volume production3 — the Micron 9650 data center SSD delivers up to two times the read performance of Gen5 at...

Read moreDetails

Micron in High-Volume Production of HBM4 Designed for NVIDIA Vera Rubin, PCIe Gen6 SSD and SOCAMM2

News highlights: HBM4 36GB 12H in high-volume production, designed for NVIDIA® Vera Rubin — greater than 2.8 TB/s1 and with 20% better power efficiency2 Industry's first PCIe® Gen6 SSD in high-volume production3 — the Micron 9650 data center SSD delivers up to two times the read performance of Gen5 at...

Read moreDetails

Schneider Electric teams with NVIDIA to develop validated blueprints to design, simulate, build, operate and maintain gigawatt-scale AI Factories

SAN JOSE, March 16, 2026 (GLOBE NEWSWIRE) -- New NVIDIA Vera Rubin reference design, co-developed with NVIDIA, provides validated roadmap for powering and cooling latest NVIDIA rack-scale systems AVEVA, the industrial software company owned by Schneider Electric, and NVIDIA develop lifecycle digital twin architecture in NVIDIA Omniverse for large-scale AI...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • Future of the Creator Economy Market (2025) | Influencer Platforms, Digital Monetization & Industry Trends | Top 5 Companies 2026: Instagram, TikTok, YouTube, Ko-fi Labs, Patreon

    6 shares
    Share 2 Tweet 2
  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    155 shares
    Share 62 Tweet 39
  • Presearch Series II Node NFT Auction Sells Out, Generates 8.5M+ PRE and Doubles Participation

    5 shares
    Share 2 Tweet 1
  • Quantum Cryptography Market Set to Surge with QKD & QRNG Adoption 2026 | Top Companies 2026 – Qasky, Qubitekk, ISARA, QuantumCTek

    6 shares
    Share 2 Tweet 2
  • Discover 2025’s Top 5 Promising Low-Cap Crypto Gems

    93 shares
    Share 37 Tweet 23
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • Stimulus Broadband Breaks Ground on Klamath County Fiber Build
  • Is The Site Flooded? Use a Well Point Dewatering Pump
  • Troubleshooting Built-in Radio Mode Issues – Tips and Tricks, Do’s and Don’ts
  • JTE Mobility Scooters: 2026 Buyer’s Guide – Tips and Tricks, Do’s and Don’ts
  • What is Potassium Dihydrogen Phosphate – Specifications and Industry Applications

RSS Latest on Block3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age

RSS Latest on Meta3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Founder’s Note
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Web3Wire Whitepaper | Tokenomics

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!

The Klyrox Protocol | The Algorithmic Monographs

Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News

Media Portfolio: Block3Wire | Meta3Wire

  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.