Skip to main content

Check your Firefox extensions today. Some may leave your system open to attack

firefox 55 adds webvr support
Popular Firefox add-ons may expose systems Kārlis Dambrāns/Flickr
It’s a good idea to check your browser extensions if you use Firefox. Nine of the 10 most popular extensions for Mozilla’s browser open computers to malware and security breaches, according to a research paper presented at the Black Hat conference by a group from Northeastern University.

Among the top Firefox add-ons, only AdBlock Plus doesn’t make your system vulnerable. The nine that do allow potential problems are Video DownloadHelper, Firebug, NoScript Security Suite, DownthemAll!, Greasemonkey, Web of Trust, Flash Video Downloader, FlashGot Mass Downloader, and Download Youtube Videos as MP4. These 10 are all available on the Mozilla website.

The problem occurs when users install Firefox add-ons. Because of the way Firefox is designed, those add-ons aren’t protected from each other. The researchers reported that an add-on with malware can “conceal its malicious behavior by invoking the capabilities of other add-ons.” The bottom line is when you download and subsequently use a trusted add-on with the vulnerability, destructive action may take place in the background while you think everything is working correctly.

Nick Nguyen, VP of product for Firefox, acknowledged the issue in a statement to Digital Trends: “The way add-ons are implemented in Firefox today allows for the scenario hypothesized and presented at Black Hat Asia. The method described relies on a popular add-on that is vulnerable to be installed, and then for the add-on that takes advantage of that vulnerability to also be installed.

“Because risks such as this one exist, we are evolving both our core product and our extensions platform to build in greater security,” continued Nguyen. “The new set of browser extension APIs that make up WebExtensions, which are available in Firefox today, are inherently more secure than traditional add-ons, and are not vulnerable to the particular attack outlined in the presentation at Black Hat Asia. As part of our electrolysis initiative – our project to introduce multi-process architecture to Firefox later this year – we will start to sandbox Firefox extensions so that they cannot share code.“

How to remove Firefox Add-ons

If have Firefox installed on your computer, here’s what you can do today.

In the upper right corner of your display, on the same line where you enter URLs, look on the far right. Click on the icon with three horizontal lines to bring up the settings menu. Click on Add-ons. An Add-on Manager browser tab will open with a menu on the upper left side of your screen. By default the menu will open the Extensions window; this is where you want to check for any of the problem add-ons we mentioned above in this article.

If you find them, our suggestion is to remove them by clicking the Remove button for each. Don’t just click the Disable button to turn them off, you want them gone, so hit Remove.

If you find and remove vulnerable add-ons, it’s a great idea to run antivirus and spam checking software on your system. Set scan options for a full system check, not just the quick check mode most virus and malware scanning programs offer. Computer security, even for single systems at home, is a never-ending concern.

Updated on April 6 at 6 p.m. PT by Jeffrey Van Camp: Firefox got back to us with a quote. We’ve updated the article, which was originally published earlier today.

Editors' Recommendations

Bruce Brown
Digital Trends Contributing Editor Bruce Brown is a member of the Smart Homes and Commerce teams. Bruce uses smart devices…
How to create a Subreddit on desktop and mobile
Laptop Working from Home

Few social media sites are as popular as Reddit. Regardless of what you're interested in, there's probably a thriving community for you to interact with on the platform. Known as subreddits, these communities are home to topics like gaming, world news, science, movies, and more. If you can't find a subreddit with your particular interest, Reddit makes it easy to create your own Reddit community.

Running a successful Reddit community isn't easy – but the process of starting one only takes a few minutes. Keep in mind that you'll want to keep a close eye on your subreddit to prevent it from being shut down or turning into a wasteland with no users, but running a subreddit can be a lot of fun when done properly. If you prefer, you can also create a private community that only your friends can join, giving you a place to hang out beyond Twitter and TikTok.

Read more
How to download music from YouTube on desktop and mobile
A woman sitting on a couch, wearing airpods and holding and looking at a smartphone.

Downloading music from YouTube is a fairly common practice, and the demand for making the process easier has inspired the creation of countless websites and software.

But not every service can be considered safe. In fact, some of these services may infect your computer with malware or produce poor-quality audio files. When downloading music from YouTube, you’ll need to first make sure that the websites or apps you use for doing so won’t hurt your device. For this guide our team has found two methods to make the process safer and easier.

Read more
How to clear your browser cache in Chrome, Edge, or Firefox
The Firefox iPhone app.

A stocked computer cache may be convenient for logging into and out of go-to sites in seconds flat, but a major buildup of these tracking codes could significantly impact your PC’s performance. If you’ve noticed that your PC has been running rather slow of late, or you’re using a new browser and don’t know how to clear its cache, we’ve got you covered with the following guide.

Read more