Published on February 26th, 2019 📆 | 6033 Views ⚑0
Duo Labs presents CRXcavator Service that analyzes Chrome Extensions
Researchers at Duo Labs has launched a new service called CRXcavator that allows users to analyze Chrome extensions and deliver security reports on them.
Researchers at Duo Labs, a division of Duo Security, has launched a new service called CRXcavatorthat allows users to analyze Chrome extensions and deliver security reports on them.
The experts released a beta version of the CRXcavator allows to analyze the permissions associated with Chrome extensions, along with many other features, and their implications.
Extensions have access to powerful functionality within the context of a browser that could be abused by threat actors, for this reason, it is important for end-user to discover malicious Chrome extensions and legitimate, benign extensions affected by security issues.
“The set of permissions an extension requests gives a good indicator of how concerned a reviewer might need to be, so CRXcavator is built on understanding the implications of the various permissions that are available for an extension to request.” reads the post published by Duo Labs.
“We have categorized and assigned an objective numerical risk score to each permission to help a security team have a metric to use when triaging extension analysis,”.
“With all these perspectives included, a CRXcavator report equips a security operations analyst to make a well-informed decision about whether to allow or block an extension,” continues Duo Labs.
Most of the extensions in the Web Store that support Content Security Policies (99%) do not have default-src or connect-src in the CSP defined (these allow developers restrict the external resources the extension can access).) Experts pointed out that 78.3% of them do not have a CSP defined,
“CRXcavator scans the full Chrome Web Store on an ongoing basis, making it easier than ever for analysts to review and stay updated on the extensions their organization has allowed or are considering allowing.” concludes Duo Labs.