Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Building Tech With No Experience Taught Me This Key Skill

    September 1, 2025

    I’ve tried 3 different smart rings but I keep going back to Apple Watch – here’s why

    September 1, 2025

    You can buy an iPhone 16 Pro for $250 off on Amazon right now – how the deal works

    September 1, 2025
    Facebook X (Twitter) Instagram
    Trending
    • Building Tech With No Experience Taught Me This Key Skill
    • I’ve tried 3 different smart rings but I keep going back to Apple Watch – here’s why
    • You can buy an iPhone 16 Pro for $250 off on Amazon right now – how the deal works
    • ‘Cyberpunk 2077’ Is Teasing Something For Three Days From Now
    • WhatsApp 0-Day, Docker Bug, Salesforce Breach, Fake CAPTCHAs, Spyware App & More
    • 5 days left: Exhibit tables are disappearing for Disrupt 2025
    • Is AI the end of software engineering or the next step in its evolution?
    • Look out, Meta Ray-Bans! These AI glasses just raised over $1M in pre-orders in 3 days
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»AI»Chrome extension privacy promises undone by hardcoded secrets, leaky HTTP
    AI

    Chrome extension privacy promises undone by hardcoded secrets, leaky HTTP

    TechurzBy TechurzJune 9, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Chrome extension privacy promises undone by hardcoded secrets, leaky HTTP
    Share
    Facebook Twitter LinkedIn Pinterest Email


    From the extensions Guo mentioned, SEMRush Rank and PI Rank transmit users’ full browsing domains in plaintext to rank.trellian.com, effectively exposing their web activity. MSN New Tab/Homepage sends a persistent Machine ID, OS version, and extension version using an unencrypted SendPingDetails request, data that can be used to track users across sessions.  

    Additionally, DualSafe Password Manager, while not leaking passwords, still pushes analytics like browser language and version to stats.itopupdate.com over HTTP.  

    “We used to call these (extensions) BHO’s – browser helper objects – and this was a very common way to compromise browsers for various outcomes, ranging from stealing credentials and spying on users, to simply establishing ways to very uniquely identify and track users across the internet,” said BugCrowd CISO Trey Ford. “Ultimately, this can manifest as a form of malware, and unavoidably create a new attack surface for miscreants to attack and compromise a very secure browsing experience.” 

    Chrome Extension hardcoded HTTP leaky privacy promises Secrets undone
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWWDC’s iOS 26 launch is the first step toward the ‘Liquid Glass’ iPhone
    Next Article Oppo A5i and A5i Pro launch with Snapdragon 6s 4G Gen 1, Pro has 6,000mAh Si/C battery
    Techurz
    • Website

    Related Posts

    AI

    I’ve tried 3 different smart rings but I keep going back to Apple Watch – here’s why

    September 1, 2025
    AI

    Is AI the end of software engineering or the next step in its evolution?

    September 1, 2025
    AI

    Google Pixel 10 Pro Fold vs. Samsung Galaxy Z Fold 7: Here’s the clear winner after testing both

    September 1, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    You Can Now Get Starlink for $15-Per-Month in New York, but There’s a Catch

    July 11, 20257 Views

    Non-US businesses want to cut back on using US cloud systems

    June 2, 20257 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    You Can Now Get Starlink for $15-Per-Month in New York, but There’s a Catch

    July 11, 20257 Views

    Non-US businesses want to cut back on using US cloud systems

    June 2, 20257 Views
    Our Picks

    Building Tech With No Experience Taught Me This Key Skill

    September 1, 2025

    I’ve tried 3 different smart rings but I keep going back to Apple Watch – here’s why

    September 1, 2025

    You can buy an iPhone 16 Pro for $250 off on Amazon right now – how the deal works

    September 1, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.