newstrooper newstrooper
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Reading: Popular Chrome Extensions leak API keys, user data over HTTP, and hardcoded credentials
Share

News Trooper

Your Global Insight, Delivered Daily.

Search
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
Follow US
© 2025 All Rights Reserved | Powered by News Trooper News
News Trooper > Technology > Popular Chrome Extensions leak API keys, user data over HTTP, and hardcoded credentials
Technology

Popular Chrome Extensions leak API keys, user data over HTTP, and hardcoded credentials

June 5, 2025 5 Min Read
Share
Popular Chrome Extensions leak API keys, user data over HTTP, and hardcoded credentials
SHARE

Cybersecurity researchers have flagged several popular Google Chrome extensions known to send data over HTTP and send hardcode secrets in code, putting users at privacy and security risks.

“Some widely used extensions (…) unintentionally send sensitive data over simple HTTP,” said Yuanjing Guo, security researcher with Symantec’s security technology and response team. “In doing so, you can publish your browsing domain, machine ID, operating system details, usage analysis, and even information in plain text.”

The fact that network traffic is not encrypted means they are susceptible to intermediate (AITM) attacks, allowing malicious actors on the same network, such as public Wi-Fi, to intercept and, worse still, to modify this data.

A list of identified extensions can be found below –

  • Semrush rank (Extension ID: idbhoeaiokcojcgappfigpifhpkjgmab) and pi rank (id: ccgdboldgdlngcgfdolahmiilojmfndl).
  • browsec vpn (id:omghfjlpggmjjaagoclmmobgdodcjboh) uses http to invoke the uninstall URL at “browsec-uninstall.s3-website.eu-central-1.amazonaws(.)com” when the user tries to extend the extension.
  • MSN New Tab (ID: LKLFBKDIGIHJAAEAMNCIBECHHGALLDGL) and MSN HomePage, Bing Search & News (ID: Midiombanaceofjhodpdibeppmnamfcj).
  • Dualsafe Password Manager & Digital Vault (ID: LGBJHDKJMPGJGCBCDLHKOKKKPJMEDGC). It constructs an HTTP-based URL request for “stats.itopupdate(.)com” along with information about the extended version, the user’s browser language, and usage “type”.

“While the credentials and passwords don’t appear to be leaked, the fact that the password manager uses unencrypted requests for telemetry erodes trust with an overall security attitude,” Guo said.

Symantec also identified another extension using API keys, secrets and tokens embedded directly in JavaScript code.

  • Online Security and Privacy Extension (ID: gomekmidlodglbbbmalcneegiecbdmki), AVG Online Security (ID: nbmoafcmbajniiapeidgficgifbfmjfo), Speed ​​Dial (FVD) – New Tab Page, 3D, Sync Tool (ID: LNBMBGOCENENHHHHDOJDIELGNMEFLBNFB), Hardcoded Google Analytics 4 (GA4) API Secrets that can be used by attackers to attack GA4 endpoints and corrupted metrics
  • equitio – Mathematics has become digital (ID: HJNGOLEFDPDNOOAMGDLDLKJGMDCMCJNC) embeds Microsoft Azure API keys used for speech recognition that can be used by attackers to inflate developer costs or exhaust usage restrictions
  • Amazing screen recorder and screenshots Scroll through (ID: NLIPOENFBBIKPBJKFPFILLCGKOBLGPMJ) and Screenshot Tools and Screen Capture (ID: MFPIAEHGJBBBFEDNOOIHADALHEHEHAHCJO).
  • Microsoft Editor – Spell & Glamour Checker (ID: GPAIOBKFHNONEDKHHFJPMHDALGEOEBFA), a telemetry key named “StatSapikey” is published to record user data for analysis.
  • Antidote Connector (ID: LMBOPDIIKKAMFHGCCKCKCJHOJNOKGFEO). It incorporates a third-party library called the InboxSDK, which contains hard-coded credentials that include API keys.
  • watch2gether (ID: CIMPFFIMGEIPDHNHJOHJOHPBEHJKCDPJOLG), this exposes the tenor gif search API key
  • Trust Wallet (ID: egjidjbpglichdcondbcbdnbeeppgdph). It exposes wallet developers an API key associated with the RAMP network, a web3 platform that allows users to buy and sell Crypto directly from the app.
  • TravelArrow – Virtual Travel Agent (ID: COPLMFNPHAHPCKNBCHEHDIKBDIEONN).
See also  Microsoft will help CBI to dismantle the Indian call centre behind Japan's technical assistance scam

Attackers who end up finding these keys can equip them with weapons to reduce API costs, host illegal content, send spoofed telemetry data, and mimic cryptocurrency trading orders.

In addition to concerns, the Antidote Connector is just one of over 90 extensions that use the InboxSDK. This means that other extensions are more susceptible to the same problem. The names of other extensions have not been disclosed by Symantec.

“From Ga4 Analytics secrets to Azure Speech Keys and AWS S3 credentials to Google-specific tokens, each of these snippets demonstrates how a few lines of code can put an entire service at risk,” says Guo. “Solution: Do not store client-side sensitive credentials.”

Developers recommend switching to HTTPS every time they send or receive data, and using Credential Management Services to securely store credentials on the backend server, rotating secrets regularly to further minimize risk.

The findings show how even popular extensions with hundreds of thousands of installations suffer from minor misunderstandings and security failures like hardcoded credentials, putting user data at risk.

“Users of these extensions should consider removing them until the developer deals with unstable (HTTP) calls,” the company said. “The risk is not theoretical. Unencrypted traffic can be easily captured and data can be used for profiling, phishing or other targeted attacks.”

“The comprehensive lesson is that large install bases or well-known brands don’t necessarily guarantee best practices regarding encryption. You need to scrutinize your extensions for the protocols and shared data you use to ensure that your information remains truly secure.”

See also  Why traditional DLP solutions fail in the browser era

Share This Article
Facebook Twitter Copy Link
Previous Article The new 94% rated strategy game is a mix of Cyberpunk and XCOM The new 94% rated strategy game is a mix of Cyberpunk and XCOM
Next Article Aid ship heading to Gaza rescues four Libyan immigrants from the Mediterranean Aid ship heading to Gaza rescues four Libyan immigrants from the Mediterranean
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News

Musk’s decision to limit political spending leaves some Republicans cold

Musk’s decision to limit political spending leaves some Republicans cold

Elon Musk's pledge to retreat from campaign spending -- if…

June 2, 2025
GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

GOP Rep. Bill Huizenga is preparing to run for Michigan's open Senate seat

McKinnack Island, Mich. -- Republican Rep. Bill Huizenga is preparing…

June 2, 2025
'It betrays our values': Progressives grapple with deadly shooting

'It betrays our values': Progressives grapple with deadly shooting

Progressive is tackling that two people who worked at the…

June 2, 2025
Beshear, Khanna to headline Dem mayor summit in July

Beshear, Khanna to headline Dem mayor summit in July

Two potential 2028 presidential primary candidates will descend on Cleveland…

June 2, 2025
Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

Democrats are ‘stuck in that unfortunate reality’ in debate over Biden's illness

24 hours after Sunday's announcement that former President Joe Biden…

June 2, 2025

You Might Also Like

Voxel51’s new automatic labeling technology promises to reduce annotation costs by 100,000 times
Technology

Voxel51’s new automatic labeling technology promises to reduce annotation costs by 100,000 times

7 Min Read
“Time to uninstall Google Chrome” Warns Cybersecurity Experts
Technology

“Time to uninstall Google Chrome” Warns Cybersecurity Experts

6 Min Read
Researchers detail the evolving tactics of bitter apt as its geographical extent expands
Technology

Researchers detail the evolving tactics of bitter apt as its geographical extent expands

5 Min Read
How to speak ChatGpt normally
Technology

How to speak ChatGpt normally

18 Min Read
newstrooper
newstrooper

Welcome to News Trooper, your reliable destination for global news that matters. In an age of information overload, we stand as a dedicated news platform committed to delivering timely, accurate, and insightful coverage of the world’s most significant events and trends.

  • Business
  • Entertainment
  • Gaming
  • Politics
  • Sports
  • Technology
  • Travel
  • World News
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • Home
  • World News
  • Politics
  • Sports
  • Entertainment
  • Business
  • Technology
  • Travel
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2025 All Rights Reserved | Powered by News Trooper News

Welcome Back!

Sign in to your account

Lost your password?