New malware restores cookies to break into your Google Account [U: Google responds]

A severe cookie-related vulnerability that first involves malware exfiltrating files from Chrome looks to allow access to Google Accounts even after passwords are changed. 

Update 1/2/24: Google is out with a response to the session token malware today. The company says it has “taken action to secure any compromised accounts detected,” and that the way to combat stolen sessions is by signing out of the affected browser — from the Account switcher in the top-right corner of any Google site — or device.

Google is aware of recent reports of a malware family stealing session tokens. Attacks involving malware that steal cookies and tokens are not new; we routinely upgrade our defenses against such techniques and to secure users who fall victim to malware. In this instance, Google has taken action to secure any compromised accounts detected. 

However, it’s important to note a misconception in reports that suggests stolen tokens and cookies cannot be revoked by the user. This is incorrect, as stolen sessions can be invalidated by simply signing out of the affected browser, or remotely revoked via the user’s devices page. We will continue to monitor the situation and provide updates as needed.

In the meantime, users should continually take steps to remove any malware from their computer, and we recommend turning on Enhanced Safe Browsing in Chrome to protect against phishing and malware downloads.


Original 12/29/23: This is according to BleepingComputer and a writeup by CloudSEK and Hudson Rock. At a high level, this vulnerability requires malware to be installed on a desktop in order to “extract and decrypt login tokens stored within Google Chrome’s local database.” 

What’s attained is then used to send a request to a Google API – normally used by Chrome to sync accounts across different Google services – and create “stable and persistent Google cookies” responsible for authentication that can be used to access your account. In this case, it’s not clear whether two-factor authentication provides any protection.

Essentially, the infusion of the key from restore files enables the reauthorization of cookies, ensuring their validity even after a password change. 

What’s most concerning is how this “restoration” process can be done multiple times if the victim never becomes aware that they’ve been compromised. Even worse is how even after a Google Account password reset, this exploit can be used one more time by the bad actor to get access to your account. 

Multiple malware groups, six by BleepingComputer’s count, have access to this vulnerability and are selling it. This exploit was first advertised in mid-November. Notably, some of these parties say they have already updated this vulnerability to combat the countermeasures Google has implemented.

We’ve reached out to Google for more information. In terms of immediate measures you can take, do not install software you’re not familiar with (as it could be malware).

Kyle Bradshaw contributed to this post.


Add 9to5Google to your Google News feed. 

FTC: We use income earning auto affiliate links. More.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Despite shortages, networking hardware market grew strongly in 2021 thumbnail

Despite shortages, networking hardware market grew strongly in 2021

Analyst firm International Data Corporation (IDC) has found that the global market for switches surged during 2021, despite shortages that have seen delivery of some products delayed for many months. Worldwide ethernet switch revenues grew at 11.8 percent year-on-year to US$8.5B in Q4 2021 while router market revenues grew at seven percent year-on-year to US$4.6B.…
Read More
The Honor 50 could cost 499 euros in Europe thumbnail

The Honor 50 could cost 499 euros in Europe

07.10.2021 17:05 | Mobile Već znamo da Honor planira povratak u Evropu, a za 26. oktobar je planirana objava Honor 50 modela. Sada je sajt WinFuture objavio detalje o ceni ovog telefona.Prema navodima, osnovni model sa 6GB RAM-a i 128GB skladišnog prostora će imati cenu od 499 evra, dok bi 8GB/256GB varijanta trebalo da košta…
Read More
Mega-Popular Muslim Prayer Apps Were Secretly Harvesting Phone Numbers thumbnail

Mega-Popular Muslim Prayer Apps Were Secretly Harvesting Phone Numbers

Photo: Pavlo Gonchar/SOPA Images/LightRocket (Getty Images)Google recently booted over a dozen apps from its Play Store—among them Muslim prayer apps with 10 million-plus downloads, a barcode scanner, and a clock—after researchers discovered secret data-harvesting code hidden within them. Creepier still, the clandestine code was engineered by a company linked to a Virginia defense contractor, which…
Read More
NRL grand final 2021: how to watch Panthers vs Rabbitohs live online thumbnail

NRL grand final 2021: how to watch Panthers vs Rabbitohs live online

Home News Entertainment (Image credit: Chris Hyde / Getty Images) It’s time for the NRL grand final, with the Penrith Panthers going head-to-head with the South Sydney Rabbitohs in Brisbane this Sunday, October 3.NRL grand final 2021• Penrith Panthers vs South Sydney Rabbitohs: Sunday, October 3 at 7:30pm AEDT• How to watch in Australia: Free-to-air…
Read More
Index Of News
Total
0
Share