/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Evernote has fixed a security flaw in its Web Clipper Chrome extension that could have allowed hackers access to users' sensitive info from third-party sites

Sergiu Gatlan / BleepingComputer :

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Evernote's Web Clipper patch lands in a crowded lane: browser extensions have been leaking user data for years, from the hidden-text-box trick that fooled Chrome, Safari, Opera and LastPass in 2017, to the extensions with up to 4M installs that fed names and passwords to Nacho Analytics just weeks before this disclosure.

Evernote is not the first vendor here to move fast — LastPass shipped fixes for its own Chrome and Opera extension bugs twice in this coverage window — but every new case reinforces that the code sitting between a user and third-party web pages is itself an attack surface.

First-order effects

  • Web Clipper users get a patched extension, closing a channel through which hackers could have pulled sensitive information from other sites they visited while the flawed version was installed.

Second-order effects

  • Every extension vendor handling credentials or page content — LastPass most visibly, given its two prior fixes in this corpus — now faces the same researcher scrutiny and the reputational cost of a disclosed leak.
  • Chrome's extension ecosystem takes another trust hit, giving Google more reason to tighten review and permission requirements for extensions that read page data.

Third-order effects

  • If the pattern holds — AVG's forced-install leak, LastPass's repeated patches, Evernote's clipper — browser extensions consolidate from a convenience layer into a regulated security perimeter, with vendors pushed toward least-privilege permissions and faster mandatory update cycles.

The trend: Browser extensions are shifting from trusted add-ons to a recurring breach vector, forcing vendors like Evernote and LastPass into continuous patch-and-disclose cycles.