$ techbeacon▋
CVE & Exploits

Critical FortiPAM Chrome Extension Flaw Enables Proxy Hijack and Tab Surveillance

Critical FortiPAM Chrome Extension Flaw Enables Proxy Hijack and Tab Surveillance

A severe security weakness has been uncovered in Fortinet's FortiPAM Chrome extension, allowing a malicious website to take control of a user's browser proxy configuration, launch new tabs at will, and record activity within those tabs. The flaw, first reported by the security research collective GBHackers, is classified as critical due to the breadth of access it grants to an attacker once a victim loads the compromised extension.

The extension, which is marketed as a tool for privileged access management within corporate environments, requests extensive permissions from Chrome, including the ability to modify proxy settings and interact with web pages. According to the analysis, the code fails to properly verify the origin of commands it receives, meaning any site that can trigger the extension's background script can issue proxy changes or inject content into newly opened tabs. This opens a pathway for attackers to reroute traffic through servers under their control and to capture credentials or other sensitive data displayed in the browser.

Experts note that the exploitation chain does not require the attacker to have direct access to the victim's machine; a simple visit to a malicious web page could be enough to activate the vulnerability. Once the proxy is altered, all subsequent web requests from the compromised browser are routed through the attacker‑controlled endpoint, facilitating man‑in‑the‑middle attacks, data exfiltration, or the distribution of additional malware. The ability to open and record tabs further expands the attack surface, enabling real‑time surveillance of user activity.

Fortinet has been alerted to the issue and is expected to issue a patch to remediate the flaw. In the interim, security professionals are advised to review the list of installed extensions, remove the FortiPAM extension if it is not essential, and enforce strict extension policies across enterprise browsers. Network administrators should also monitor proxy configuration changes for anomalies that could indicate exploitation.

The discovery underscores the broader risk posed by third‑party browser extensions, which can silently gain high‑privilege capabilities and become vectors for sophisticated attacks. As organizations continue to adopt zero‑trust models and rely on cloud‑based security tools, ensuring that extensions are regularly audited and updated remains a crucial component of a robust security posture.

Source: GBHackers
Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related