Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

AVG Forcibly Installs Vulnerable Chrome Extension That Exposes Users' Browsing History
softpedia ^ | 29 Dec 2015, 02:20 GMT | Catalin Cimpanu

Posted on 12/28/2015 6:57:10 PM PST by Utilizer

The AVG Web TuneUp Chrome extension, forcibly added to Google Chrome browsers when users were installing the AVG antivirus, had a serious flaw that allowed attackers to get the user's browsing history, cookies, and more.

The vulnerability was discovered by Google Project Zero researcher, Tavis Ormandy, who worked with AVG for the past two weeks to fix the issue. AVG Web TuneUp vulnerable to an universal XSS

As Mr. Ormandy explains in his bug report, the AVG Web TuneUp extension, which lists over nine million users on its Chrome Web Store page, was vulnerable to trivial XSS (cross-site scripting) attacks.

Attackers aware of this problem would have been able to access a user's cookies, browsing history, and various other details exposed via Chrome.

"This extension adds numerous JavaScript APIs to Chrome, apparently so that they can hijack search settings and the new tab page," explains Mr. Ormandy. "The installation process is quite complicated so that they [AVG] can bypass the Chrome [Store] malware checks, which specifically tries to stop abuse of the [Chrome] Extension API."

(Excerpt) Read more at news.softpedia.com ...


TOPICS: Computers/Internet
KEYWORDS: avg; chrome; malware; security; windowspinglist
Chrome and AVG problem!
1 posted on 12/28/2015 6:57:10 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer

I dropped AVG a few years back, when they dropped in the rankings due to inability to identify and remove certain malware. They had been at the top of the rankings prior to that.


2 posted on 12/28/2015 7:16:46 PM PST by Dalberg-Acton
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

If you install AVG they can install the AVG toolbar which is not easy to uninstall. Superantispyware and malwarebytes would not remove it when I had earlier this year as I read they “overlook” some adware.

Use Adwcleaner to remove it.
https://toolslib.net/downloads/viewdownload/1-adwcleaner


3 posted on 12/28/2015 7:25:02 PM PST by minnesota_bound
[ Post Reply | Private Reply | To 1 | View Replies]

To: minnesota_bound
I think I did a from scratch reboot of FF because of the AVG toolbar.

PITA to find and reinstall all the add-ons/extensions that I wanted, not to mention a few other tweaks that changed eons ago, and forgot about.

4 posted on 12/28/2015 7:44:30 PM PST by Calvin Locke
[ Post Reply | Private Reply | To 3 | View Replies]

To: Utilizer

Don’t use Chrome...memory hog. Any anti virus that installs tool bars are enemies of the people!


5 posted on 12/28/2015 7:44:56 PM PST by Dallas59 (Only a fool stumbles on things behind him.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; amigatec; AppyPappy; arnoldc1; ...
Anyone still using AVG? Reconsider ... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

6 posted on 12/28/2015 7:48:51 PM PST by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Dalberg-Acton

I’ve never used it but it seems to be quite popular so users might wish to have a look at this...


7 posted on 12/28/2015 7:51:00 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 2 | View Replies]

To: minnesota_bound

I thought you had to click the “allow” button for the toolbar to be installed?


8 posted on 12/28/2015 7:52:44 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Utilizer

I have always views AVG as a virus.


9 posted on 12/28/2015 7:59:43 PM PST by FreeAtlanta (Restore Liberty!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer
Freepers running AVG and using Chrome:

From the article:

"Version 4.2.5.169 of AVG Web TuneUp fixed this issue."

That can be downloaded here.

10 posted on 12/28/2015 8:01:28 PM PST by TChad
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer; ~Kim4VRWC's~; 1234; Abundy; Action-America; acoulterfan; AFreeBird; Airwinger; Aliska; ...
AVG anti-virus installs a plug-in for Google/Alphabet Chrome with a vulnerability in it that allows malicious hackers access to data on your computer. Since there is a version of AVG for Mac as well as for Windows, it would be wise to avoid AVG until they get this fixed for both platforms on your Macs. -- PING!


Apple AVG Anti-Virus Security for both Windows & Mac
Ping!

The latest Apple/Mac/iOS Pings can be found by searching Keyword "ApplePingList" on FreeRepublic's Search.

If you want on or off the Mac Ping List, Freepmail me

11 posted on 12/28/2015 8:37:11 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

AVG used to be my anti-virus of choice, but they jumped the shark a few years ago and became total crap, and nagware besides. Wouldn’t have it on one of my machines on a bet now.


12 posted on 12/28/2015 8:38:58 PM PST by Still Thinking (Freedom is NOT a loophole!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: FreeAtlanta
I have always views AVG as a virus.

When AVG first came out, it was excellent. Small, fast, and unobtrusive. Then it got bloated, slow, and in-your-face. I dropped it for AVast. . . and then later for just running Windows Security Essentials.

13 posted on 12/28/2015 8:39:45 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue....)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Utilizer

A lot of crapware is now set stop that their bringalongware installs by default unless you UNcheck it, plus they intentionally make it confusing so it looks like you’re accepting the thing you wanted. Scumware.


14 posted on 12/28/2015 8:41:55 PM PST by Still Thinking (Freedom is NOT a loophole!)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Utilizer

No man, chrome extensions are things that make the end of your tailpipes look cool.


15 posted on 12/28/2015 9:04:20 PM PST by SaxxonWoods (Trump and/or Cruz, it's all good.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Still Thinking

I’ve noticed that, but I’ve been quite careful to look closely at all the options and open every tab to make certain I always Un-check anything I did not wish to be installed.

For those few that did not provide an option to uncheck something so as to not install it, well, that particular program did not get installed.


16 posted on 12/28/2015 9:18:20 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 14 | View Replies]

To: SaxxonWoods

I never needed them. My tailpipes were ALL chrome, along with the engine casing, carb filter cover, forward foot controls, 6-in overstock front end, and dual stacked headlights.

Wheelrims, handlebars and mirrors as well, of course.


17 posted on 12/28/2015 9:22:33 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Utilizer

I run a 4” over girder, jockey shift, suicide clutch.


18 posted on 12/28/2015 10:11:25 PM PST by ROCKLOBSTER (Celebrate "Republicans Freed the Slaves Month")
[ Post Reply | Private Reply | To 17 | View Replies]

To: Still Thinking

“AVG used to be my anti-virus of choice, but they jumped the shark a few years ago and became total crap, and nagware besides.”

yep.


19 posted on 12/28/2015 10:15:13 PM PST by catnipman (Cat Nipman: Vote Republican in 2012 and only be called racist one more time!)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Utilizer

Beware of anything that’s “free” in the Internet of Things.

Microsoft Security Essentials/Defender work just fine for the majority of home users.


20 posted on 12/29/2015 4:06:58 AM PST by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 1 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson