This Firefox add-on forces other extensions to steal your data
Millions of Firefox users face brand new attack

Firefox extensions are exposing millions of users to a new bug capable of stealing sensitive data, it has been claimed.
An attacker can create a malicious add-on for Mozilla's web browser, which can then disguise its nature by forcing a legitimate, existing add-on, to do its dirty work for it, reports Ars Technica.
The flaw, dubbed an extension reuse vulnerability by the researchers who revealed it at the Black Hat security conference in Singapore, is able to do this because Mozilla has not isolated add-ons in its browser.
This means the bug can take advantage of vulnerabilities in other add-ons a user has enabled, and route its attacks through them instead.
These buggy add-ons include NoScript, Video DownloadHelper, FlashGot and Firebug, the researchers wrote in the paper.
The extensions send the user to malicious websites, or force them to download malware.
As quoted by Ars Technica, the researchers said: "These vulnerabilities allow a seemingly innocuous extension to reuse security-critical functionality provided by other legitimate, benign extensions to stealthily launch confused deputy-style attacks.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Malicious extensions that utilise this technique would be significantly more difficult to detect by current static or dynamic analysis techniques, or extension vetting procedures."
However, it does rely on a user first downloading the malicious add-on, as well as having buggy extensions already enabled on their browser.
Mozilla admitted to Ars that such a bug would work in its Firefox browser, adding: "Because risks such as this one exist, we are evolving both our core product and our extensions platform to build in greater security. The new set of browser extension APIs that make up WebExtensions, which are available in Firefox today, are inherently more secure than traditional add-ons, and are not vulnerable to the particular attack outlined in the presentation at Black Hat Asia."
-
Global cybersecurity spending is set to rise 12% in 2025 – here are the industries ramping up investment
News Global cybersecurity spending is expected to surge this year, fueled by escalating state-sponsored threats and the rise of generative AI, according to new analysis from IDC.
By Ross Kelly Published
-
Google Cloud is leaning on all its strengths to support enterprise AI
Analysis Google Cloud made a big statement at its annual conference last week, staking its claim as the go-to provider for enterprise AI adoption.
By Rory Bathgate Published
-
Spanish spyware outfit uncovered, develops exploits for Windows, Chrome, and Firefox
News Google was only able to discover the company after an anonymous submission was made to its Chrome bug reporting programme
By Zach Marzouk Published
-
Firefox 95 boosts protection against zero-day attacks
News Mozilla's browser now takes a more granular approach to walling off code
By Danny Bradbury Published
-
Mozilla to end support for Firefox Lockwise password manager
News Replacement service already lined up as browser specialist continues to streamline business
By Bobby Hellard Published
-
Firefox available on Microsoft Store for first time
News Gecko-based browser arrives after Microsoft removes restrictions
By Danny Bradbury Published
-
Why I’m leading a browser double life
Opinion There are benefits to using more than one browser
By Barry Collins Published
-
Mozilla fixes two Firefox zero-days being actively exploited
News Critical vulnerabilities allow attackers to execute arbitrary code or trigger crashes
By Carly Page Published
-
Firefox activates DNS over HTTPS for US users by default
News The privacy push, which encrypts all web traffic, has angered ISPs and regulators
By Keumars Afifi-Sabet Published
-
How to enable private browsing on any browser to keep your search history secret
In-depth Whether it's Google Chrome, Mozilla Firefox, or Microsoft Edge, here’s how to enable private browsing on every major browser
By Connor Jones Published