Internet

Chrome vulnerability: New Phishing Attack Exploits Chrome Application Mode

Google will phase out support for Chrome apps in favor of Progressive Web Apps (PWAs) and standard web technologies. A new attack scheme for phishing now shows that this is important for security reasons. Beginning with Chrome 109 or later, Google will completely phase out Chrome apps on Windows, macOS, and Linux.

Until then, users should be extra careful when signing up online for services and web apps. Hackers can use “app mode” in Chromium browsers for covert phishing attacks, as security researcher mr.d0x now explains.

It becomes extremely difficult for users to see through the scam. A new phishing technique exploits the “Application Mode” feature in Chromium-based web browsers to create “realistic desktop phishing applications”. Cybercriminals can use this to recreate login windows and obtain sensitive user data, warns mr.d0x.

Application mode is designed to launch the website in a separate browser window while simultaneously displaying the website’s favicon and hiding the address bar.

More attacks devised

According to security researcher mr.d0x, who also developed the browser-in-the-browser (BitB) attack method earlier this year, a malicious actor can exploit this behavior to use some HTML/CSS tricks to create a fake address bar at the top of the window and trick users into entering their credentials in deceptive login forms. “Although this technique is more intended for internal phishing, it can technically also be used in an external phishing scenario,” says mr.d0x.

Advanced Phishing Attacks

In addition, the attacker-controlled phishing site can use JavaScript to perform other actions, such as: For example, closing the window immediately after entering credentials, or resizing and positioning the window to achieve the desired effect.

The mechanism works for Windows, macOS, and Linux, making it a potential cross-platform threat. However, the success of the attack depends on the attacker already having access to the target’s machine

Recent Posts

Microsoft finally wants to fix Xbox download problems

Fluctuating rates, overloaded servers and frozen updates often plague Xbox users. Microsoft is now intervening…

13 hours ago

ClickFix attack discovered: Hackers spread harmful help on Steam

An attack campaign is currently underway in the Steam discussion forums, in which criminals pose…

13 hours ago

Samsung Galaxy: New cell phone batteries with a step backwards in terms of longevity

Samsung is equipping its new folding smartphones with modern silicon-carbon batteries. This brings more capacity…

13 hours ago

Exchange Online: Stupid email glitch sends too much into quarantine

Many Exchange Online users are struggling with unexpected problems. A bug suddenly moves harmless emails…

13 hours ago

Microsoft solves Azure problem: Updates and Store are running again

After a widespread failure of the Azure infrastructure, central Windows services are working again. Users…

13 hours ago

Ryzen 7 9800HX3D: AMD is probably planning an affordable gaming laptop CPU

AMD is reportedly preparing a new X3D laptop processor for demanding gamers. The upcoming CPU…

13 hours ago