SB2017081614 - Backdoor in Social Fixer Google Chrome extension



SB2017081614 - Backdoor in Social Fixer Google Chrome extension

Published: August 16, 2017

Security Bulletin ID SB2017081614
Severity
Critical
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Backdoor (CVE-ID: N/A)

The vulnerability allows a remote attacker to gain unauthorized access to victim's browser.

The vulnerability exists due to presence of backdoor code in Social Fixer Google Chrome extension 20.1.1, distributed via Google Web Store.



Remediation

Install update from vendor's website.