Guardio Labs has uncovered a significant vulnerability, designated CVE-2024–21388, in the Microsoft Edge browser, allowing attackers to exploit a private API to install browser extensions without user consent. Initially intended for marketing purposes, this flaw could enable the covert installation of extensions with broad permissions, posing serious security risks. The vulnerability, promptly disclosed to Microsoft in November 2023, was swiftly addressed, leading to a resolution in February 2024. Guardio Labs detailed the exploit process, showcasing a Proof of Concept (POC) code and emphasizing the broader security implications. This incident underscores the ongoing challenge of balancing user experience with cybersecurity, highlighting the importance of collaborative security efforts. The vulnerability stemmed from the utilization of the open-source Chromium engine by Microsoft Edge since April 2021. By analyzing configuration files and customized code within Edge's resources, Guardio Labs identified a private API accessible from Microsoft-affiliated websites. This API, designed to integrate marketing features seamlessly, inadvertently allowed the silent installation of browser extensions. Exploitation of the vulnerability could occur through cross-site scripting (XSS) attacks or the deployment of minimal privileged extensions, enabling adversaries to install malicious extensions silently. While Microsoft swiftly addressed the issue, Guardio Labs stresses the need for ongoing vigilance and proactive vulnerability management in the Chromium framework.
Researchers have uncovered an active phishing campaign targeting Brazilian organizations that abuses the legitimate NinjaOne Remote Monitoring and Management (RMM) platform to gain...
Kyushu Electric Power Co., Inc., one of Japan’s largest regional electricity providers serving the Kyushu region, has disclosed a physical security incident that may have exposed...
French officials have disclosed a cybersecurity incident involving Tchap, the secure messaging application used by government employees and public-sector organizations across Franc...