Skip to main content

Check your Firefox extensions today. Some may leave your system open to attack

firefox 55 adds webvr support
Popular Firefox add-ons may expose systems Kārlis Dambrāns/Flickr
It’s a good idea to check your browser extensions if you use Firefox. Nine of the 10 most popular extensions for Mozilla’s browser open computers to malware and security breaches, according to a research paper presented at the Black Hat conference by a group from Northeastern University.

Among the top Firefox add-ons, only AdBlock Plus doesn’t make your system vulnerable. The nine that do allow potential problems are Video DownloadHelper, Firebug, NoScript Security Suite, DownthemAll!, Greasemonkey, Web of Trust, Flash Video Downloader, FlashGot Mass Downloader, and Download Youtube Videos as MP4. These 10 are all available on the Mozilla website.

The problem occurs when users install Firefox add-ons. Because of the way Firefox is designed, those add-ons aren’t protected from each other. The researchers reported that an add-on with malware can “conceal its malicious behavior by invoking the capabilities of other add-ons.” The bottom line is when you download and subsequently use a trusted add-on with the vulnerability, destructive action may take place in the background while you think everything is working correctly.

Nick Nguyen, VP of product for Firefox, acknowledged the issue in a statement to Digital Trends: “The way add-ons are implemented in Firefox today allows for the scenario hypothesized and presented at Black Hat Asia. The method described relies on a popular add-on that is vulnerable to be installed, and then for the add-on that takes advantage of that vulnerability to also be installed.

“Because risks such as this one exist, we are evolving both our core product and our extensions platform to build in greater security,” continued Nguyen. “The new set of browser extension APIs that make up WebExtensions, which are available in Firefox today, are inherently more secure than traditional add-ons, and are not vulnerable to the particular attack outlined in the presentation at Black Hat Asia. As part of our electrolysis initiative – our project to introduce multi-process architecture to Firefox later this year – we will start to sandbox Firefox extensions so that they cannot share code.“

How to remove Firefox Add-ons

If have Firefox installed on your computer, here’s what you can do today.

In the upper right corner of your display, on the same line where you enter URLs, look on the far right. Click on the icon with three horizontal lines to bring up the settings menu. Click on Add-ons. An Add-on Manager browser tab will open with a menu on the upper left side of your screen. By default the menu will open the Extensions window; this is where you want to check for any of the problem add-ons we mentioned above in this article.

If you find them, our suggestion is to remove them by clicking the Remove button for each. Don’t just click the Disable button to turn them off, you want them gone, so hit Remove.

If you find and remove vulnerable add-ons, it’s a great idea to run antivirus and spam checking software on your system. Set scan options for a full system check, not just the quick check mode most virus and malware scanning programs offer. Computer security, even for single systems at home, is a never-ending concern.

Updated on April 6 at 6 p.m. PT by Jeffrey Van Camp: Firefox got back to us with a quote. We’ve updated the article, which was originally published earlier today.

Editors' Recommendations

Bruce Brown
Digital Trends Contributing Editor Bruce Brown is a member of the Smart Homes and Commerce teams. Bruce uses smart devices…
How to enable picture-in-picture for YouTube on your Mac
Macbook Air

If you want to have a bit of music playing in the background or want to have your favorite YouTube video running in the corner of your screen, then the picture-in-picture YouTube feature needs to be on your radar. This allows you to turn your YouTube videos into a tiny pop-up window that can be moved and repositioned around your screen.

Mac users have several ways to activate the feature, including support on both Safari and Google Chrome. There's also a nifty Chrome extension that simplifies the task to a single button press. Here's a look at how to enable picture-in-picture for YouTube on your Mac.

Read more
How to change your Gmail password
pilot testing drivers licenses internet rolls two us states password

Changing your Gmail password is incredibly important for your online security. If you're anything like the average user, your Gmail account is linked to dozens of other organizations and programs – and if your account gets hacked, there's no telling what sort of damage can be done.

Because of this, it's crucial to change your Gmail password at regular intervals. Google makes this a rather painless process, and it should take no more than a few seconds from start to finish.

Read more
Best Buy deals: Save on laptops, TVs, appliances, and more
best buy shuts down insignia line smart home products store 2 768x768

Best Buy is always a great retailer to turn to if you’re looking for some savings. There are almost always Best Buy deals taking place on TVs, appliances, and devices we use to navigate the digital world. In fact, right now at Best Buy you can find some of the best TV deals, best laptop deals, and best phone deals that can be shopped, and we haven’t even mentioned the deals on tablets and home audio equipment currently taking place at Best Buy. We’ve rounded up all of the best Best Buy deals you can shop right now and categorized them for your convenience below, so read onward for some great opportunities to save.
Best Buy TV deals

There may be no better place to purchase one of the best TVs than Best Buy. There is almost always some huge savings to find on TVs at Best Buy, and that’s certainly the case right now. You’ll find deals top TV brands like Sony, Samsung, and LG, and more budget-friendly brands like TCL and Hisense are in play, too.

Read more