[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5cOWgVIZGTRWmNoUZIDMJVkUwrN4GCq8aUV5IYomfS8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"18611de3-465d-41d0-aca1-33a354bbb8a8","152-malicious-chrome-extensions-harvested-user-data-via-ad-fraud","713a219d-b428-4190-aed3-1136ab0e5b80","152 Malicious Chrome Extensions Harvested User Data via Ad Fraud","A coordinated network of 152 Chrome browser extensions disguised as live wallpaper tools secretly tracked user behavior, fabricated organic search traffic, and redirected users to monetized ad sites. The root cause lies in inadequate vetting of third-party browser extensions and users' lack of awareness about the risks of installing unverified software. This matters because browser extensions operate with elevated privileges, giving them broad access to browsing history, form inputs, and session data. The scheme also highlights weaknesses in platform-level enforcement, as the Chrome Web Store failed to detect the policy violations at scale before widespread installation occurred.","**Immediate actions:**\n- Audit all currently installed browser extensions across your organization and remove any that are unverified, unused, or recently flagged.\n- Block installation of browser extensions from unvetted publishers using enterprise browser management policies (e.g., Google Admin Console or Group Policy).\n\n**Long-term improvements:**\n- Maintain an approved allowlist of browser extensions and enforce it organization-wide through endpoint management tools.\n- Implement a formal third-party software vetting process that includes privacy policy review and permission scope analysis before any extension is approved.\n- Integrate browser extension inventory into your asset and configuration management program for continuous visibility.\n\n**Detection measures:**\n- Deploy endpoint detection tools capable of monitoring anomalous browser extension behavior, such as unexpected outbound connections or DOM manipulation.\n- Establish alerts for installation of new or unapproved browser extensions on managed endpoints.\n- Periodically review network traffic logs for patterns consistent with ad fraud or covert data exfiltration from browser processes.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 4: Secure Configuration of Enterprise Assets and Software","CIS Control 13: Network Monitoring and Defense","NIST SP 800-53 CM-7: Least Functionality","NIST SP 800-53 SI-7: Software, Firmware, and Information Integrity","NIST SP 800-53 AC-6: Least Privilege","GDPR Article 5(1)(a): Lawfulness, Fairness, and Transparency","GDPR Article 25: Data Protection by Design and by Default","NIST CSF PR.DS-5: Protections Against Data Leaks","NIST CSF ID.SC-3: Supply Chain Risk Management","published","2026-06-17T14:20:51.940891+00:00","2026-06-17T14:20:51.831+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fhackread.com\u002Fchrome-live-wallpaper-extensions-ad-track-fake-search-clicks\u002F","152-chrome-live-wallpaper-extensions-hid-ad-tracking-and-fake-search-clicks-8cd1ae","152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fake Search Clicks",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]