Check your Firefox extensions today. Some may leave your system open to attack

firefox 55 adds webvr support
Popular Firefox add-ons may expose systems Kārlis Dambrāns/Flickr
It’s a good idea to check your browser extensions if you use Firefox. Nine of the 10 most popular extensions for Mozilla’s browser open computers to malware and security breaches, according to a research paper presented at the Black Hat conference by a group from Northeastern University.

Among the top Firefox add-ons, only AdBlock Plus doesn’t make your system vulnerable. The nine that do allow potential problems are Video DownloadHelper, Firebug, NoScript Security Suite, DownthemAll!, Greasemonkey, Web of Trust, Flash Video Downloader, FlashGot Mass Downloader, and Download Youtube Videos as MP4. These 10 are all available on the Mozilla website.

The problem occurs when users install Firefox add-ons. Because of the way Firefox is designed, those add-ons aren’t protected from each other. The researchers reported that an add-on with malware can “conceal its malicious behavior by invoking the capabilities of other add-ons.” The bottom line is when you download and subsequently use a trusted add-on with the vulnerability, destructive action may take place in the background while you think everything is working correctly.

Nick Nguyen, VP of product for Firefox, acknowledged the issue in a statement to Digital Trends: “The way add-ons are implemented in Firefox today allows for the scenario hypothesized and presented at Black Hat Asia. The method described relies on a popular add-on that is vulnerable to be installed, and then for the add-on that takes advantage of that vulnerability to also be installed.

“Because risks such as this one exist, we are evolving both our core product and our extensions platform to build in greater security,” continued Nguyen. “The new set of browser extension APIs that make up WebExtensions, which are available in Firefox today, are inherently more secure than traditional add-ons, and are not vulnerable to the particular attack outlined in the presentation at Black Hat Asia. As part of our electrolysis initiative – our project to introduce multi-process architecture to Firefox later this year – we will start to sandbox Firefox extensions so that they cannot share code.“

How to remove Firefox Add-ons

If have Firefox installed on your computer, here’s what you can do today.

In the upper right corner of your display, on the same line where you enter URLs, look on the far right. Click on the icon with three horizontal lines to bring up the settings menu. Click on Add-ons. An Add-on Manager browser tab will open with a menu on the upper left side of your screen. By default the menu will open the Extensions window; this is where you want to check for any of the problem add-ons we mentioned above in this article.

If you find them, our suggestion is to remove them by clicking the Remove button for each. Don’t just click the Disable button to turn them off, you want them gone, so hit Remove.

If you find and remove vulnerable add-ons, it’s a great idea to run antivirus and spam checking software on your system. Set scan options for a full system check, not just the quick check mode most virus and malware scanning programs offer. Computer security, even for single systems at home, is a never-ending concern.

Updated on April 6 at 6 p.m. PT by Jeffrey Van Camp: Firefox got back to us with a quote. We’ve updated the article, which was originally published earlier today.

Movies & TV

Did I really watch that? Here's how to delete your Netflix viewing history

Everybody has some skeletons in their streaming closet, but you don't have to live with them if you don't want to. Learning how to delete your Netflix viewing history is easy, and we're here to help.

Give your eyes a break with these handy blue light filters

Filtering blue light from your monitor is a great way to make long days of work easier on your eyes, especially when it gets later in the day. You can use ones built into MacOS and Windows, or one of the third-party options.

How to easily record your laptop screen with apps you already have

Learning how to record your computer screen shouldn't be a challenge. Lucky for you, our comprehensive guide lays out how to do so using a host of methods, including both free and premium utilities, in both MacOS and Windows 10.

Calibrate your display to get it looking just the way you like it

Want to see images the way they're intended to be seen? Here is our quick guide on how to calibrate your monitor using your operating system or another tool, to make what's on the screen look as good as it can.

Switch up your Reddit routine with these interesting, inspiring, and zany subs

So you've just joined the wonderful world of Reddit and want to explore it. With so many subreddits, however, navigating the "front page of the internet" can be daunting. Here are some of the best subreddits to get you started.

Use one of these password managers to help protect yourself online

The internet can be a scary place, especially if you don't have a proper password manager. This guide will show you the best password managers you can get right now, including both premium and free options.

Is the 5G spectrum harmful to our health? Experts say, 'Don't freak out'

There's plenty of consumer anxiety about radiofrequency (RF) radiation, specifically around millimeter waves (mmWave) used on 5G networks, but is it based in reality? We asked the FDA to give us its official view on the subject.

YouTube beats Apple, Netflix as the most trusted brand by millennials

The popular video sharing website YouTube climbed up in an annual Mblm study, moving up from third place in 2018 and coming ahead of both Apple and Netflix in final 2019 rankings. 

Russia will ‘unplug’ from the internet as part of a cyber-defense test

Authorities across Russia are planning on unplugging the country from the global internet as part of a test of its cyber defenses. The disconnection will briefly keep all internet traffic inside the country.

These are the coolest games you can play on your Google Chrome browser right now

Not only is Google Chrome a fantastic web browser, it's also a versatile gaming platform that you can access from just about anywhere. Here are a few of our favorite titles for the platform.

Gmail adds lots of new functionality to its right-click menu

Right-click on an email in Gmail and the list of actions is pretty limited. That's about to change, though, as Google has just announced it's expanding the list of options to make its email client that little bit more useful.

Tired of paying a monthly fee for Word? The best Microsoft Office alternatives

Looking for a competent word processor that isn't Microsoft Word? Thankfully, the best alternatives to Microsoft Office offer robust features, expansive compatibility, and an all-too-familiar aesthetic. Here are our favorites.

File Transfer Protocol explained: What FTP is and what it does

FTP stands for "File Transfer Protocol," and it's used to transfer files online. Most internet users don't need it, but web developers use it constantly. Here's what FTP is, how it works, and how you can get started using it.

Make a GIF of your favorite YouTube video with these great tools

Making a GIF from a YouTube video is easier today than ever, but choosing the right tool for the job isn't always so simple. In this guide, we'll teach you how to make a GIF from a YouTube video with our two favorite online tools.