Technology
Chrome, Firefox browser extensions leaked millions of users' data
Washington, July 20
Popular browser extensions like ad blockers have been caught harvesting personal data of millions of consumers who use Chrome and Firefox -- not only their browsing histories but also exposing tax returns, medical records, credit card information and other sensitive data in the public domain.
According to an independent cyber security researcher Sam Jadali, the data has been leaked to a fee-based company called Nacho Analytics that gives unlimited access to any websites analytics data.
The data could be purchased for as little as $10 to $50, said Jadali whose report was first described in Ars Technica late on Friday.
"This non-stop flow of sensitive data over the past seven months has resulted in the publication of links to home and business surveillance videos hosted on Nest and other security services.
"Tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive, Intuit.com, and other online services" have been exposed, said the report.
The exposed data via eight browser extensions also include vehicle identification, numbers of recently bought automobiles, along with the names and addresses of the buyers.
Patient details, travel itineraries, Facebook Messenger attachments and Facebook photos, even private, are now available in the public domain.
Browser extensions - also known as plug-ins or add-ons - are apps that consumers can install to run alongside their browser for additional functionality.
The affected extensions were apps used by millions of people, including HoverZoom, SpeakIt!, and FairShare Unlock.
"The extensions have been remotely removed or disabled in consumers' browsers and are no longer available for download," said both Google and Firefox.
People who didn't download the extensions may also be affected.
"Nobody is immune to this. Even if you don't have any harmful extensions, the other people you interact with may have an extension on their computers that could be leaking the data you share with them," Jadali was quoted as saying.
Nacho Analytics, for example, promises to let people "see anyone's analytics account" and to provide "real-time web analytics for any website".
The company charges $49 per month, per domain, to monitor any of the top 5,000 most widely-trafficked websites.
The security expert has suggested users to delete all browser extensions they have installed in the past.
According to an independent cyber security researcher Sam Jadali, the data has been leaked to a fee-based company called Nacho Analytics that gives unlimited access to any websites analytics data.
The data could be purchased for as little as $10 to $50, said Jadali whose report was first described in Ars Technica late on Friday.
"This non-stop flow of sensitive data over the past seven months has resulted in the publication of links to home and business surveillance videos hosted on Nest and other security services.
"Tax returns, billing invoices, business documents, and presentation slides posted to, or hosted on, Microsoft OneDrive, Intuit.com, and other online services" have been exposed, said the report.
The exposed data via eight browser extensions also include vehicle identification, numbers of recently bought automobiles, along with the names and addresses of the buyers.
Patient details, travel itineraries, Facebook Messenger attachments and Facebook photos, even private, are now available in the public domain.
Browser extensions - also known as plug-ins or add-ons - are apps that consumers can install to run alongside their browser for additional functionality.
The affected extensions were apps used by millions of people, including HoverZoom, SpeakIt!, and FairShare Unlock.
"The extensions have been remotely removed or disabled in consumers' browsers and are no longer available for download," said both Google and Firefox.
People who didn't download the extensions may also be affected.
"Nobody is immune to this. Even if you don't have any harmful extensions, the other people you interact with may have an extension on their computers that could be leaking the data you share with them," Jadali was quoted as saying.
Nacho Analytics, for example, promises to let people "see anyone's analytics account" and to provide "real-time web analytics for any website".
The company charges $49 per month, per domain, to monitor any of the top 5,000 most widely-trafficked websites.
The security expert has suggested users to delete all browser extensions they have installed in the past.

35 minutes ago
Feels like something divine, blessing from past life: Indian diaspora overjoyed after meeting PM Modi in Buenos Aires

52 minutes ago
PM Modi begins historic Argentina visit by paying tribute to country's liberator

1 hour ago
Trump says Iran may restart nuclear programme "at a different location", calls it "a problem"

4 hours ago
Hamas submits "positive response" to US-backed Gaza ceasefire deal

4 hours ago
Trump announces plans to host UFC fight at White House for nation's 250th year of independence

4 hours ago
24 die in Texas floods, Trump calls inundation 'terrible'

4 hours ago
Musk threatens Republicans over Trump's 'big, beautiful bill', sparks internal rift

4 hours ago
Trump's 'One Big Beautiful' Tax and Spending Law: A New Era of Economic Redesign

5 hours ago
Ryo Tatsuki's tsunami prediction shook Japan; a heavy blow to the tourism sector; loss estimated at ₹30,000 crore.

8 hours ago
Release of Anushka Shetty, Vikram Prabhu-starrer 'Ghaati' postponed

8 hours ago
Goldmine: Sanju Rathod of ‘Gulabi Sadi’ fame says, there’s a lot to explore in Marathi music

8 hours ago
Makers of Prabhas's The Raja Saab condole demise of Hollywood star Michael Madsen

8 hours ago
Niharika Chouksey calls his Tum Se Tum Tak co-star Sharad Kelkar 'a very good human being'