Thursday, June 26, 2025
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

SquareX Discloses “Browser Syncjacking,” a New Attack Technique that Provides Full Browser and Device Control, Putting Millions at Risk

January 30, 2025
in Artificial Intelligence, GlobeNewswire, Web3
Reading Time: 9 mins read
5
SHARES
246
VIEWS
Share on TwitterShare on LinkedInShare on Facebook

Screenshot 2025-01-27 130951

SquareX discloses a new attack technique that shows how malicious extensions can be used to completely hijack the browser, and eventually, the whole device.

PALO ALTO, Calif., Jan. 30, 2025 (GLOBE NEWSWIRE) — Browser extensions have been under the spotlight in enterprise security news recently due to the wave of OAuth attacks on Chrome extension developers and data exfiltration attacks. However, until now, due to the limitations browser vendors place on the extension subsystem and extensions, it was thought to be impossible for extensions to gain full control of the browser, much less the device.

SquareX researchers Dakshitaa Babu, Arpit Gupta, Sunkugari Tejeswara Reddy and Pankaj Sharma debunked this belief by demonstrating how attackers can use malicious extensions to escalate privileges to conduct a full browser and device takeover, all with minimal user interaction. Critically, the malicious extension only requires read/write capabilities present in the majority of browser extensions on the Chrome Store, including common productivity tools like Grammarly, Calendly, and Loom, desensitizing users from granting these permissions. This revelation suggests that virtually any browser extension could potentially serve as an attack vector if created or taken over by an attacker. To the best of our understanding, extensions submitted to the Chrome Store requesting these capabilities are not put through additional security scrutiny at the time of this writing.

The browser syncjacking attack can be broken up into three parts: how the extension silently adds a profile managed by the attacker, hijacks the browser and eventually gains full control of the device.

Profile Hijacking

The attack begins with an employee installing any browser extension – this could involve publishing one that masquerades as an AI tool or taking over existing popular extensions that may have up to millions of installations in aggregate. The extension then “silently” authenticates the victim into a Chrome profile managed by the attacker’s Google Workspace. This is all done in an automated manner in a background window, making the whole process almost imperceptible to the victim. Once this authentication occurs, the attacker has full control over the newly managed profile in the victim’s browser, allowing them to push automated policies such as disabling safe browsing and other security features.

Using a very clever social engineering attack that exploits trusted domains, the adversary can then further escalate the profile hijacking attack to steal passwords from the victim’s browser. For example, the malicious extension can open and modify Google’s official support page on how to sync user accounts to prompt the victim to perform the sync with just a few clicks. Once the profile is synced, attackers have full access to all credentials and browsing history stored locally. As this attack only leverages legitimate sites and has no visible sign that it has been modified by the extension, it will not trigger any alarm bells in any security solutions monitoring the network traffic.

Browser Takeover

To achieve a full browser takeover, the attacker essentially needs to convert the victim’s Chrome browser into a managed browser. The same extension monitors and intercepts a legitimate download, such as a Zoom update, and replaces it with the attacker’s executable, which contains an enrollment token and registry entry to turn the victim’s Chrome browser into a managed browser. Thinking that they downloaded a Zoom updater, the victim executes the file, which ends up installing a registry entry that instructs the browser to become managed by the attacker’s Google Workspace. This allows the attacker to gain full control over the victim’s browser to disable security features, install additional malicious extensions, exfiltrate data and even silently redirect users to phishing sites. This attack is extremely potent as there is no visual difference between a managed and unmanaged browser. For a regular user, there is no telltale sign that a privilege escalation has occurred unless the victim is highly security aware and goes out of their way to regularly inspect their browser settings and look for associations with an unfamiliar Google Workspace account.

Device Hijacking

With the same downloaded file above, the attacker can additionally insert registry entries required for the malicious extension to message native apps. This allows the extension to directly interact with local apps without further authentication. Once the connection is established, attackers can use the extension in conjunction with the local shell and other available native applications to secretly turn on the device camera, capture audio, record screens and install malicious software – essentially providing full access to all applications and confidential data on the device.

The browser syncjacking attack exposes a fundamental flaw in the way remote-managed profiles and browsers are managed. Today, anyone can create a managed workspace account tied to a new domain and a browser extension without any form of identity verification, making it impossible to attribute these attacks. Unfortunately, most enterprises currently have zero visibility into the browser – most do not have managed browsers or profiles, nor any visibility to the extensions employees are installing often based on trending tools and social media recommendations.

What makes this attack particularly dangerous is that it operates with minimal permissions and nearly no user interaction, requiring only a subtle social engineering step using trusted websites – making it almost impossible for employees to detect. While recent incidents like the Cyberhaven breach have already compromised hundreds, if not thousands of organizations, those attacks required relatively complex social engineering to operate. The devastatingly subtle nature of this attack – with an extremely low threshold of user interaction – not only makes this attack extremely potent, but also sheds light on the terrifying possibility that adversaries are already using this technique to compromise enterprises today.

Unless an organization chooses to completely block browser extensions via managed browsers, the browser syncjacking attack will completely bypass existing blacklists and permissions-based policies. SquareX’s founder, Vivek Ramachandran, says, “This research exposes a critical blind spot in enterprise security. Traditional security tools simply can’t see or stop these sophisticated browser-based attacks. What makes this discovery particularly alarming is how it weaponizes seemingly innocent browser extensions into complete device takeover tools, all while flying under the radar of conventional security measures like EDRs and SASE/SSE Secure Web Gateways. A Browser Detection-Response solution isn’t just an option anymore – it’s a necessity. Without visibility and control at the browser level, organizations are essentially leaving their front door wide open to attackers. This attack technique demonstrates why security needs to ‘shift up’ to where the threats are actually happening: in the browser itself.”

SquareX has been conducting pioneering security research on browser extensions, including the DEF CON 32 talk Sneaky Extensions: The MV3 Escape Artists that revealed multiple MV3 compliant malicious extensions. This research team was also the first to discover and disclose the OAuth attack on Chrome extension developers one week before the Cyberhaven breach. SquareX was also responsible for the discovery of Last Mile Reassembly attacks, a new class of client-side attacks that exploits architectural flaws and completely bypasses all Secure Web Gateway solutions. Based on this research, SquareX’s industry-first Browser Detection and Response solution protects enterprises against advanced extension-based attacks including device hijacking attempts by conducting dynamic analysis on all browser extension activity at runtime, providing a risk score to all active extensions across the enterprise and further identifying any attacks that they may be vulnerable to.

For more information about the browser syncjacking attack, additional findings from this research are available at sqrx.com/research.

About SquareX

SquareX helps organizations detect, mitigate and threat-hunt client-side web attacks happening against their users in real time.

SquareX’s industry-first Browser Detection and Response (BDR) solution, takes an attack-focused approach to browser security, ensuring enterprise users are protected against advanced threats like malicious QR Codes, Browser-in-the-Browser phishing, macro-based malware and other web attacks encompassing malicious files, websites, scripts, and compromised networks.

Additionally, with SquareX, enterprises can provide contractors and remote workers with secure access to internal applications, enterprise SaaS, and convert the browsers on BYOD / unmanaged devices into trusted browsing sessions.

Contact

Head of PR

Junice Liew

SquareX

junice@sqrx.com

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/d184d7d1-727f-4b63-8629-932464610908

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.
ShareTweet1ShareSendShare2
Previous Post

Neighbors Federal Credit Union Makes Loan Funding Easier While Fighting Fraud with Point Predictive’s AutoPass™ Solution

Next Post

Churches Cultivate Deeper Connections and Greater Generosity in 2024 with Pushpay

Related Posts

IQAI Pakistan Strategy Seminar Concludes Successfully, Deeply Empowering Local Traders

The IQAI Pakistan Strategy Seminar recently concluded with great success at the Flatties Hotel in Lahore. As a key component of IQAI’s global community-building initiative, the event attracted enthusiastic participation from a wide range of local cryptocurrency traders and blockchain professionals. Featured speaker Umar Rana, a prominent figure in Pakistan’s...

Read moreDetails

Nextech3D.ai Signs New Enterprise Contract For Volume AI-Driven 3D Model Production

New agreement kicks off with 5,000 AI-generated 3D models and positions Nextech3D.ai to scale production of high-volume 3D models, meeting growing global demand from retailers and eCommerce platforms NEW YORK CITY, NY AND TORONTO, ON / ACCESS Newswire / June 26, 2025 / Nextech3D.ai (OTCQX:NEXCF)(CSE:NTAR)(FSE:1SS), an AI-first technology company that...

Read moreDetails

Locus FS Announces Executive Appointments and Strategic Market Focus

Solon, OH, June 26, 2025 --(PR.com)-- Locus Fermentation Solutions (Locus FS), a biotechnology company delivering microbial and glycolipid-based performance additives, unveiled a new leadership vision and commercial strategy focused on performance-driven growth in four key sectors. With a seasoned CEO and newly appointed board of directors, the company is focusing on...

Read moreDetails

Bunnyshell Unveils Autonomous Multi-Agent System that Containerizes Any Codebase

San Franscico, CA, June 26, 2025 --(PR.com)-- Bunnyshell has launched its Multi-Agent Containerization System (MACS), an AI-powered platform that transforms raw code repositories into production-ready Docker and Compose assets with zero manual work. Early users report that MACS cuts containerization time from weeks to under an hour.Alin Dobra, Founder at Bunnyshell,...

Read moreDetails

Telliant Systems Launches “The Innovator’s Playbook” Podcast Series with Expert Voices on Tech and Strategy

Alpharetta, GA, June 26, 2025 --(PR.com)-- Telliant Systems is proud to announce the debut of its brand new podcast series, “The Innovator’s Playbook.” A dynamic platform for in-depth discussions and expert interviews, the series covers a spectrum of agile, forward-thinking topics—from early-stage strategy to enterprise transformation.“The Innovator’s Playbook” features weekly/bi weekly...

Read moreDetails

United States 3D Printing Materials Market 2025 Edition Size, Share & Report 2033

Market Overview 2025-2033United States 3D printing materials market size reached USD 790.4 Million in 2024. Looking forward, IMARC Group expects the market to reach USD 3,815.6 Million by 2033, exhibiting a growth rate (CAGR) of 17.05% during 2025-2033. The market is expanding due to rising demand for diverse, performance‐optimized materials,...

Read moreDetails

JazzJoyandRoy.com Shuts Up, Listens To Pastor Ken Lunkins

Famous painting created for Jazz Joy and Roy Global Radio by Kathryn Diane Gray is now available for less than 5 million bucks When speaking with wise individuals, announcers have a tendency to talk more than normal to show off their own wisdom. The featured DJ on one global radio...

Read moreDetails

AI Infrastructure Industry Outlook 2025-2029: Market Set to Cross $223.84 Billion Milestone

AI Infrastructure Stay ahead with our updated market reports featuring the latest on tariffs, trade flows, and supply chain transformations.How Large Will the AI Infrastructure Market Size By 2025?The market size for AI infrastructure has seen a significant increase in the past few years. The market is projected to expand...

Read moreDetails

Transformative Trends Impacting the Vehicle-to-Vehicle (V2V) Communication Market Landscape: Technological Advancements In The Vehicle-To-Vehicle Communications Market

Vehicle-to-Vehicle (V2V) Communication Stay ahead with our updated market reports featuring the latest on tariffs, trade flows, and supply chain transformations.How Large Will the Vehicle-to-Vehicle (V2V) Communication Market Size By 2025?The size of the vehicle-to-vehicle (V2V) communication market has seen significant expansion in the most recent years. The market is...

Read moreDetails

3D Semiconductor Packaging Market Expected to Achieve 15.7% CAGR by 2029: Growth Forecast Insights

3D Semiconductor Packaging Stay ahead with our updated market reports featuring the latest on tariffs, trade flows, and supply chain transformations.How Large Will the 3D Semiconductor Packaging Market Size By 2025?The market for 3D semiconductor packaging has witnessed significant expansion in the past few years. Its size is forecasted to...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    66 shares
    Share 26 Tweet 17
  • Top Cross-Chain DeFi Solutions to Watch by 2025

    36 shares
    Share 14 Tweet 9
  • Discover 2025’s Top 5 Promising Low-Cap Crypto Gems

    55 shares
    Share 22 Tweet 14
  • Top 5 Wallets for Seamless Multi-Chain Trading in 2025

    35 shares
    Share 14 Tweet 9
  • ReggaeEDM Takes The Stage

    7 shares
    Share 3 Tweet 2
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

Web 3.0 and AI Summit 2025

2025-09-11
Frankfurt
Summit

Latest on Web3Wire

  • Simplify Labs Joins Hands with Top Fintech Firms to Deliver Full-Spectrum MiCA-Compliant Crypto Infrastructure
  • Torram launches dApp challenge with 3M tokens up for grabs to bring institutional DeFi apps natively to Bitcoin
  • Bety Casino Raises the Stakes: New VIP Program Delivers Exclusive Crypto Gaming Benefits for High-Value Players
  • IQAI Pakistan Strategy Seminar Concludes Successfully, Deeply Empowering Local Traders
  • Amaze and Picsart Partner to Turn Picsart Designs into Physical and Digital Products That Can Be Sold Globally

RSS Latest on Block3Wire

  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age
  • Cathedra Bitcoin Announces Leasing of 2.5-MW Bitcoin Mining Facility
  • Global Web3 Payments Leader, Banxa, Announces Integration With Metis to Usher In Next Wave of Cryptocurrency Users
  • Dexalot Launches First Hybrid DeFi Subnet on Avalanche

RSS Latest on Meta3Wire

  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
  • MetatronAI.com Unveils Revolutionary AI-Chat Features and Interface Upgrades
  • Purely.website – Disruptive new platform combats rising web hosting costs
  • WEMADE and Metagravity Sign Strategic Alliance MOU to Collaborate on Blockchain Games for the Metaverse
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Whitepaper | Tokenomics

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Media Portfolio: Block3Wire | Meta3Wire

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!
Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News
  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.