'Fixed' Chrome extension flaw could allow hackers to record both your webcam and desktop feeds - Gaming News google.com, pub-1884294887586162, DIRECT, f08c47fec0942fa0
Gaming News
No Result
View All Result
  • PC
  • PlayStation
  • Xbox
  • Nintendo
  • Crypto Gaming
  • Reviews
  • Metaverse
  • Videos
  • PC
  • PlayStation
  • Xbox
  • Nintendo
  • Crypto Gaming
  • Reviews
  • Metaverse
  • Videos
No Result
View All Result
Gaming News
No Result
View All Result

‘Fixed’ Chrome extension flaw could allow hackers to record both your webcam and desktop feeds

May 25, 2022
in PC
0 0
0
0
VIEWS
Share on FacebookShare on Twitter



Ever get that feeling you’re being watched? If you’ve currently got the Screencastify Chrome extension active, you could be. A flaw the company claimed was ‘fixed’ may still allow malicious actors to access unsuspecting users’ webcam and desktop activity, and record it for whatever they see fit. 

You’ve probably seen these ‘sextortion’ emails: “We have a recording of you doing X, Y, Z. Send us $10,000 in some obscure cryptocurrency or we’ll release the vid for all the world to see.” 

With over 10,000,000 installs, Screencastify caters to a range of companies such as Webflow, Teachable, Atlassian, Netlifyrunning, Marketo, and ZenDesk. It’s an extension that lets users record, edit and submit video content for work and school projects, so users include teachers, and schoolchildren at various stages of their education. I can only imagine the panic from parents when the vulnerability was discovered, and their potential fury knowing it still hasn’t been properly fixed.

According to Bleeping Computer (opens in new tab), a cross-site scripting (XSS) vulnerability in the Screencastify software was reported by security researcher Wladimir Palant on February 14, 2022. Devs behind the Chrome extension promptly sent out a supposed fix, but Palant has made it clear the app is still putting users in a vulnerable position for exploitation, and extortion.

On installing Screencastify, it asks to access your Google Drive and makes a permanent Google OAuth access token for the company’s account. The cloud folders created with the token, in which all the users video projects are saved, are allegedly let unhidden. 

Chrome’s desktopCapture API and tabCapture permissions are also granted automatically when you install the software, meaning it has the ability to record your desktop too.

On top of this, the software’s WebRTC API permission is only requested once, meaning the capture functions are continuously enabled from the get go, unless you switch the setting to ‘ask permission’ each time. Even then, Palant found that hackers could not only steal the authentication token, but also use the Screencastify app to record without notifying the user at all.

“Not much appears to have changed here, and I could verify that it is still possible to start a webcam recording without any visual clues,” Palant explains in their research blog post (opens in new tab).

“The problem was located in the error page displayed if you already submitted a video to a challenge and were trying to submit another one.” And since the error page has a fixed address, “it can be opened directly rather than triggering the error condition.”

Both Bleeping Computer and Palant have contacted Screencastify, but to no avail. 

Here’s a quick glance over the Screencastify privacy policy:

“We use security and technology measures consistent with industry standards to try to protect your information and make sure that it is not lost, damaged or accessed by anyone who should not see it.”

“Despite our security measures, we cannot guarantee the absolute security of your personal information.”

Here’s hoping the vulnerability is sorted properly, and soon, before rogue employees or hackers start making use of the exploit. Best to use a different platform for the time being, perhaps.



Source link

Previous Post

Bonuses for online casinos – PlayStation Universe

Next Post

Dominican Republic Hotel To Use NFTs As Reservation Tools

Next Post
Dominican Republic Hotel To Use NFTs As Reservation Tools

Dominican Republic Hotel To Use NFTs As Reservation Tools

Recommended

WildSino: A Contemporary Tackle On-line On line casino Gaming

May 26, 2026

AmunRa On line casino: Γρήγορες Συνεδρίες Spin για Φίλους Υψηλής Έντασης Slots

May 26, 2026

Prime on line casino din Romnia Platforme on-line cu aplicaii cellular moderne.1550

May 26, 2026

Spinsy On line casino en France avantages et rcompenses pour les joueurs actifs.333

May 26, 2026

Gaming News

Get latest Gaming News on Pley2win.com. Popular Games, New released, Gaming Review, Xbox gaming, PlayStation, PC, Mobile Gaming and More!!

Categories

  • ! Valorant Boosting Tips
  • ! Без рубрики
  • 1
  • 10
  • 1000A Z
  • 1090A Z
  • 111
  • 18.12.1
  • 1win-np.com
  • 1xbetapp-ph.com3
  • 2000A Z
  • 237-Spassino Casino
  • 274 BeepBeep Casino –
  • 3
  • 318 Wizebets Italy
  • 4
  • 44
  • 5
  • 50%A 50 Z
  • 50%A 50B Z
  • 507-Pelican Casino
  • 777casino
  • 8
  • 800A 200BA Z
  • a16z generative ai
  • adobe generative ai 3
  • adobe generative ai 8
  • Article
  • Avocasino
  • bahisyasal 4521
  • Blog
  • Bookkeeping
  • Boomerang Casino
  • BT prod 5715
  • Business, Small Business
  • Casino
  • Casino De Arturo
  • casinocatspins
  • casinopinco
  • casinowazamba
  • catspinscasino
  • CH
  • Chicken Road rules
  • chickenroad
  • CIB
  • cresuscasino
  • Crypto Gaming
  • dec_bh_common
  • dec_bh_main
  • dec_pb_common
  • December
  • dushscience.in
  • EC
  • edeka-halmschlag.de
  • Efbet Jackpots
  • Featured News
  • FinTech
  • first
  • Forex News
  • Forex Trading
  • Games
  • Gaming News
  • generative ai adobe photoshop 3
  • ghostinocasino
  • giochi
  • gokspel
  • hautarzt-rw.de
  • impressariocasino
  • jan4
  • jeux
  • jeuxi
  • Leon Casino
  • Leonbet
  • Live
  • Live Στοίχημα
  • lobby303sky.info
  • madnixcasino
  • Metaverse
  • Mobile Στοίχημα
  • mostbet
  • NEW
  • New Released
  • News
  • ninecasino
  • Nintendo
  • nko-zdrav.ru
  • nov2
  • nov6
  • novos-casinos
  • Online Casino
  • online καζίνο
  • PC
  • pinco
  • platinumslotscasino
  • PlayStation
  • Plinko
  • Plinko Online Casino
  • Popular
  • Post
  • Public
  • ready_text
  • Reviews
  • Rolldorado
  • rubds1010.ru 10
  • sep
  • Sex
  • Sober living
  • spel
  • Spellen
  • spiderbetscasino
  • Spiele
  • spiller1
  • Sport
  • Stake
  • tenexcasino
  • test
  • Trading
  • trends
  • Uncategorized
  • VeryWell Casino
  • Videos
  • voxcasino
  • vrclub-tron.ru 10
  • vulkanvegascasino
  • what to name your ai
  • Wildrobin
  • wildz
  • wildzcasino
  • www.xin-chao.de
  • Xbox
  • zuplay-in.com2
  • Αθλητικά Στοιχήματα
  • Καζίνο
  • Φρουτάκια
  • Блог
  • Новости Криптовалют
  • Текста
  • Финтех
  • Форекс Брокеры56

Follow us

  • DMCA
  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2022 - Pley 2 Win.

No Result
View All Result
  • PC
  • PlayStation
  • Xbox
  • Nintendo
  • Crypto Gaming
  • Reviews
  • Metaverse
  • Videos

Copyright © 2022 - Pley 2 Win.

Welcome Back!

Login to your account below

Forgotten Password? Sign Up

Create New Account!

Fill the forms below to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.