Backdoor in Infinity New Tab (Chrome extension) - #VU7960

 

Backdoor in Infinity New Tab (Chrome extension) - #VU7960

Published: August 16, 2017 / Updated: November 22, 2018


Vulnerability identifier: #VU7960
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-798
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to victim's browser.

The vulnerability exists due to presence of backdoor code in Infinity New Tab Google Chrome extension 3.12.3, distributed via Google Web Store.



Affected software

Infinity New Tab (Chrome extension)

Remediation

Update to version 6.0.0 or later.


External References

Related Security Bulletins