Evernote has fixed a security flaw in its Web Clipper Chrome extension that could have allowed hackers access to users' sensitive info from third-party sites
Sergiu Gatlan / BleepingComputer :
Context & Ripple Effects
Evernote's Web Clipper patch lands in a crowded lane: browser extensions have been leaking user data for years, from the hidden-text-box trick that fooled Chrome, Safari, Opera and LastPass in 2017, to the extensions with up to 4M installs that fed names and passwords to Nacho Analytics just weeks before this disclosure.
Evernote is not the first vendor here to move fast — LastPass shipped fixes for its own Chrome and Opera extension bugs twice in this coverage window — but every new case reinforces that the code sitting between a user and third-party web pages is itself an attack surface.
First-order effects
- Web Clipper users get a patched extension, closing a channel through which hackers could have pulled sensitive information from other sites they visited while the flawed version was installed.
Second-order effects
- Every extension vendor handling credentials or page content — LastPass most visibly, given its two prior fixes in this corpus — now faces the same researcher scrutiny and the reputational cost of a disclosed leak.
- Chrome's extension ecosystem takes another trust hit, giving Google more reason to tighten review and permission requirements for extensions that read page data.
Third-order effects
- If the pattern holds — AVG's forced-install leak, LastPass's repeated patches, Evernote's clipper — browser extensions consolidate from a convenience layer into a regulated security perimeter, with vendors pushed toward least-privilege permissions and faster mandatory update cycles.
The trend: Browser extensions are shifting from trusted add-ons to a recurring breach vector, forcing vendors like Evernote and LastPass into continuous patch-and-disclose cycles.