Researchers: Attackers could use holes in Firefox add-ons to target your PC

It goes without saying that any given piece of computer code—be it an app, a part of your operating system, or even a browser plug-in—may contain flaws that could leave your PC open to attack. But a team of researchers from Northwestern University have come across a new method of attack that can take advantage of holes in one or more installed Firefox add-ons.

According to the team’s research paper (PDF), this newly discovered attack “leverages capability leaks from legitimate extensions to avoid the inclusion of security-sensitive API calls within the malicious extension itself.”

To read this article in full or to leave a comment, please click here

Researchers: Attackers could use holes in Firefox add-ons to target your PC