Internet users should exercise caution while installing Google Chrome extensions as the company has removed over 100 malicious links after they were found collecting "sensitive" user data, country's cyber-security agency said on Wednesday.
The Indian Computer Emergency Response Team of India (CERT-In), the national technology arm to combat cyber-attacks and safeguard Indian cyberspace, said it has also been found that these extensions contained code to bypass Google Chrome's Web store security scans. The malicious extensions had the ability to take screenshots, read the clipboard, harvest authentication cookies or grab user keystrokes to read passwords and other confidential information, it said.
"These extensions, reportedly posed as tools to improve Web searches, convert files between different formats as security scanners and more," it added.
The federal cyber-security agency suggested users to uninstall Google Chrome extensions with IDs given in the IOCs (organisational chart) section.
Users can visit the Chrome extensions page and subsequently enable developer mode to see if they have installed any of the malicious extensions and then remove them from their browsers, it said.
The agency advised Internet users to only install extensions which are absolutely needed and refer user reviews before doing so.
They should uninstall extensions which are not in use, it said, adding that users should not install extensions from unverified sources.
WWDC 2020 had a lot of exciting announcements from Apple, but which are the best iOS 14 features for India? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.