Backdoor in Chrometana (Chrome extension) - #VU7956

 

Backdoor in Chrometana (Chrome extension) - #VU7956

Published: August 16, 2017 / Updated: November 22, 2018


Vulnerability identifier: #VU7956
CSH Severity: Critical
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Red
CVE-ID: N/A
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild
Vendor: Chrometana
Affected software:
Chrometana (Chrome extension)

Detailed vulnerability description

The vulnerability allows a remote attacker to gain unauthorized access to victim's browser.

The vulnerability exists due to presence of backdoor code in Chrometana Google Chrome extension 1.1.3, distributed via Google Web Store.



Remediation

Update to version 2.0.0.

Sources