AVG auto-installs vulnerable Chrome extension 01-01-2016, 11:48 PM
#1
I'm not really sure whether this fits in with world news or not, but I figured I'd put it here since it's a pretty big deal for the 9 million Chrome users that were affected by it.
https://code.google.com/p/google-securit...ail?id=675
https://www.reddit.com/r/netsec/comments...extension/
For more information follow the links.
https://code.google.com/p/google-securit...ail?id=675
https://www.reddit.com/r/netsec/comments...extension/
Quote:When a user installs AVG AntiVirus, a Chrome extension called "AVG Web TuneUp" with extension id chfdnecihphmhljaaejmgoiahnihplgn is force-installed. I can see from the webstore statistics it has nearly 9 million active Chrome users.
https://chrome.google.com/webstore/detai...gn/reviews
This extension adds numerous JavaScript API's to chrome, apparently so that they can hijack search settings and the new tab page. The installation process is quite complicated so that they can bypass the chrome malware checks, which specifically tries to stop abuse of the extension API.
Anyway, many of the API's are broken, the attached exploit steals cookies from avg.com. It also exposes browsing history and other personal data to the internet, I wouldn't be surprised if it's possible to turn this into arbitrary code execution.
For more information follow the links.

![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)










![[Image: qcYJ3l.png]](https://i.skull.moe/u/qcYJ3l.png)







