RiSec.n0tst3 17 February 2022
Multiple Chrome browser extensions make use of a session token for Meta’s Facebook that grants access to signed-in users’ social network data in a way that violates the company’s policies and leaves users open to potential privacy violations. Security researcher Zach Edwards last week noted that Brave had blocked a Chrome extension called L.O.C. out of concern it exposed the user’s Facebook data to a third-party server without any notice or permission prompt. L.O.C. utilized an access token that can be easily obtained from Facebook’s Creator Studio web app. After extracting...