Security company solutions are supposed to help protect the computers of millions of users. At the same time, developers are only human, and a mistake or two can slip through at the last moment. But the case of the AVG Web TuneUp extension for Google Chrome was so severe that it set off a whole series of reactions in Mountain View, including its temporary ban from the Chrome Web Store.
The Issue 675 report
Fast forward to December 15. On a discussion list belonging to Google Security Research, Tavis Ormandy — a researcher we have mentioned previously — published the so-called 'Issue 675', describing a serious security flaw caused by the AVG Web TuneUp extension for Google Chrome. According to Ormandy, when a user installs AVG Antivirus, the installer adds the extension to the browser forcibly. Ormandy explains that the extension injects several JavaScript APIs into Chrome, allowing it to hijack elements such as search parameters and the 'new tab' page. He also notes that the installation process is very complicated, because it needs to bypass all of Chrome's internal malware checks that are meant to prevent this kind of abuse.
A security disaster
In short, the extension was a true security disaster. Ormandy did not have to make a great effort to create an exploit capable of stealing cookies from avg.com, the browsing history and other user data. With a bit more work, he could have turned it into an attack ready to provide remote code execution, but he decided to contact AVG and explain the situation. The exchange was not pleasant: the extension causes so many problems that Ormandy did not know whether to report it as a vulnerability or escalate it to the extension research team to declare it a PUP (Potentially Unwanted Program). And there is more: AVG presented a new version of the extension, however, all it did was apply a 'whitelist' for all requests that have 'avg.com' in their name... which, incidentally, can be bypassed with a 'man-in-the-middle' attack.
Patch and suspension
The definitive patch for AVG Web TuneUp was delivered on December 28, but installations of the extension were suspended until further notice, while the Chrome Web Store team investigates a possible violation of terms by AVG. This suspension does not affect updates, and all who have the extension in their browser (9 million active users) should receive the new version. An AVG spokesperson said that the installation of Web TuneUp is completely optional... but that is not exactly the point. The point is that the extension compromised the entire browser to take control of two elements inside it. Personally, I think AVG has run out of credit.