<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>擴充功能 &#8211; 科技島-掌握科技新聞、科技職場最新資訊</title>
	<atom:link href="https://www.technice.com.tw/tag/%e6%93%b4%e5%85%85%e5%8a%9f%e8%83%bd/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.technice.com.tw</link>
	<description>專注於科技新聞、科技職場、科技知識相關資訊，包含生成式AI、人工智慧、Web 3.0、區塊鏈、科技職缺百科、生物科技、軟體發展、雲端技術等豐富內容，適合熱衷科技及從事科技專業人事第一手資訊的平台。</description>
	<lastBuildDate>Wed, 22 Oct 2025 08:42:26 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.4.2</generator>

<image>
	<url>https://www.technice.com.tw/wp-content/uploads/2022/12/cropped-wordpress_512x512-150x150.png</url>
	<title>擴充功能 &#8211; 科技島-掌握科技新聞、科技職場最新資訊</title>
	<link>https://www.technice.com.tw</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>瀏覽器擴充功能成資安破口？駭客如何靜悄悄植入惡意程式</title>
		<link>https://www.technice.com.tw/techmanage/infosecurity/193519/</link>
					<comments>https://www.technice.com.tw/techmanage/infosecurity/193519/#respond</comments>
		
		<dc:creator><![CDATA[孫敬]]></dc:creator>
		<pubDate>Thu, 25 Sep 2025 09:39:56 +0000</pubDate>
				<category><![CDATA[資安]]></category>
		<category><![CDATA[生活]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[擴充功能]]></category>
		<category><![CDATA[瀏覽器]]></category>
		<guid isPermaLink="false">https://www.technice.com.tw/?p=193519</guid>

					<description><![CDATA[<p><img width="1200" height="627" src="https://www.technice.com.tw/wp-content/uploads/2024/01/02_0-4.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Chrome" decoding="async" srcset="https://www.technice.com.tw/wp-content/uploads/2024/01/02_0-4.jpg 1200w, https://www.technice.com.tw/wp-content/uploads/2024/01/02_0-4-300x157.jpg 300w, https://www.technice.com.tw/wp-content/uploads/2024/01/02_0-4-1024x535.jpg 1024w, https://www.technice.com.tw/wp-content/uploads/2024/01/02_0-4-768x401.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" title="瀏覽器擴充功能成資安破口？駭客如何靜悄悄植入惡意程式 1"></p>
<p>資安公司Synacktiv的研究發現，駭客可以透過直接修改這些檔案，在使用者毫無察覺的情況下，強制瀏覽器載入任何擴充功能，甚至完全繞過官方的Chrome線上應用程式商店。<content><span style="font-weight: 400;">記者孫敬／編譯</span></p>
<p><span style="font-weight: 400;">許多人可能不知道，包括Chrome、Edge和Brave在內的Chromium瀏覽器，擴充功能的設定檔都儲存在一個名為 </span><span style="font-weight: 400;">%AppData%\Google\User Data\Default\Preferences</span><span style="font-weight: 400;"> 或 </span><span style="font-weight: 400;">Secure Preferences</span><span style="font-weight: 400;"> 的JSON檔案中。資安公司Synacktiv的研究發現，駭客可以透過直接修改這些檔案，在使用者毫無察覺的情況下，強制瀏覽器載入任何擴充功能，甚至完全繞過官方的Chrome線上應用程式商店。</span></p>
<p><b>延伸閱讀：<span style="color: #33cccc;"><a style="color: #33cccc;" href="https://www.technice.com.tw/techmanage/infosecurity/193273/" target="_blank" rel="noopener">全新釣魚郵件手法？駭客假冒GitHub官方通知竊取開發者帳密</a></span></b></p>
<p>[caption id="attachment_89955" align="aligncenter" width="1200"]<img class="wp-image-89955 size-full" src="https://www.technice.com.tw/wp-content/uploads/2024/01/02_0-4.jpg" alt="Chrome" width="1200" height="627" /> 擴充功能的設定檔成為駭客鎖定的目標。（圖／科技島資料照）[/caption]</p>
<h2><b>駭客行動前需要完成的三個步驟</b></h2>
<p><span style="font-weight: 400;">這種攻擊手法之所以能夠成功，主要有三個技術上的關鍵：</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">預先計算擴充功能ID：駭客必須準確計算出擴充功能的ID。這個ID是由擴充功能的公鑰或安裝路徑，經過SHA-256雜湊演算法計算，再轉換成特定的字母組合。</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">生成有效的訊息認證（MAC）：為了繞過瀏覽器的完整性檢查，駭客需要為擴充功能和開發者模式標誌生成有效的MAC。這需要駭客逆向工程瀏覽器內部的HMAC演算法，並使用正確的靜態密鑰來簽名。</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">繞過企業資安政策：企業環境通常會透過群組原則物件（GPO）來設定白名單或黑名單，控制哪些擴充功能可以被安裝。</span></li>
</ul>
<h2><b>三大進階手法，突破企業防線</b></h2>
<p><span style="font-weight: 400;">駭客並不會輕易被企業的資安政策阻擋。Synacktiv的研究進一步揭示了三種高階的規避方法，讓他們能夠成功突破防線：</span></p>
<ol>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">盜用合法擴充功能的ID：駭客可以重複使用企業已批准的擴充功能（例如Adobe Acrobat Reader）的RSA公鑰，來生成一個相同的擴充功能ID。接著，他們將一個惡意的未封裝擴充功能（unpacked extension）注入到這個ID下，藉此繞過依賴雜湊值來檢測的白名單。</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">利用「ID碰撞」悄悄替換：當一個未封裝的擴充功能與一個從商店安裝的擴充功能擁有相同的ID時，Chromium瀏覽器會優先載入這個未封裝的版本。這種「ID碰撞」的特性，使得駭客能夠神不知鬼不覺地用惡意程式覆蓋掉受信任的擴充功能。</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">修改登錄檔移除政策：即使企業部署了政策，駭客也可以透過刪除或修改Windows登錄檔中的相關項目，直接移除瀏覽器擴充功能的白名單或黑名單，從而完全繞過政策限制。</span></li>
</ol>
<h2><b>如何防禦幽靈擴充功能的威脅？</b></h2>
<p><span style="font-weight: 400;">一旦這些惡意擴充功能被成功植入，駭客就能進行各種惡意行為，例如：攔截網路流量、竊取使用者連線紀錄、執行背景服務，甚至是將惡意程式碼注入到目標網頁中。Synacktiv的概念驗證工具也證實了，駭客能夠透過遠端部署與客製化的C2伺服器，在瀏覽器中執行JavaScript，進而繞過各種加密保護。</span></p>
<p><span style="font-weight: 400;">為了有效防禦這種新型攻擊，企業與個人用戶必須提高警覺，採取以下防護措施：</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">監控核心檔案：監控瀏覽器設定檔是否有未經授權的變更。</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">驗證登錄檔完整性：定期檢查Windows登錄檔，確保企業政策沒有被惡意篡改。</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">偵測異常擴充功能註冊：建立偵測機制，即時發現異常的擴充功能安裝行為。</span></li>
</ul>
<p><span style="font-weight: 400;">若缺乏這些偵測與防禦機制，這種被稱為「幽靈擴充功能」（Phantom Extensions）的攻擊手法，將成為駭客在企業內部進行資料竊取與橫向移動的絕佳途徑。</span></p>
<p><span style="font-weight: 400;">資料來源：<span style="color: #33cccc;"><a style="color: #33cccc;" href="https://cybersecuritynews.com/chromium-browsers-windows-arbitrary-extensions/" target="_blank" rel="noopener">Cyber Security News</a></span></span></content></p>
<p>這篇文章 <a rel="nofollow" href="https://www.technice.com.tw/techmanage/infosecurity/193519/">瀏覽器擴充功能成資安破口？駭客如何靜悄悄植入惡意程式</a> 最早出現於 <a rel="nofollow" href="https://www.technice.com.tw">科技島-掌握科技新聞、科技職場最新資訊</a>。</p>
]]></description>
		
					<wfw:commentRss>https://www.technice.com.tw/techmanage/infosecurity/193519/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>微軟宣布Microsoft Editor將於10月底退役 功能將內建於Edge瀏覽器</title>
		<link>https://www.technice.com.tw/techmanage/infosecurity/190429/</link>
					<comments>https://www.technice.com.tw/techmanage/infosecurity/190429/#respond</comments>
		
		<dc:creator><![CDATA[孫敬]]></dc:creator>
		<pubDate>Wed, 03 Sep 2025 06:29:06 +0000</pubDate>
				<category><![CDATA[資安]]></category>
		<category><![CDATA[生活]]></category>
		<category><![CDATA[編輯精選]]></category>
		<category><![CDATA[Edge]]></category>
		<category><![CDATA[Microsoft Editor]]></category>
		<category><![CDATA[微軟]]></category>
		<category><![CDATA[擴充功能]]></category>
		<guid isPermaLink="false">https://www.technice.com.tw/?p=190429</guid>

					<description><![CDATA[<p><img width="1280" height="800" src="https://www.technice.com.tw/wp-content/uploads/2025/09/Microsoft-Editor.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Microsoft Editor" decoding="async" srcset="https://www.technice.com.tw/wp-content/uploads/2025/09/Microsoft-Editor.jpg 1280w, https://www.technice.com.tw/wp-content/uploads/2025/09/Microsoft-Editor-300x188.jpg 300w, https://www.technice.com.tw/wp-content/uploads/2025/09/Microsoft-Editor-1024x640.jpg 1024w, https://www.technice.com.tw/wp-content/uploads/2025/09/Microsoft-Editor-768x480.jpg 768w" sizes="(max-width: 1280px) 100vw, 1280px" title="微軟宣布Microsoft Editor將於10月底退役 功能將內建於Edge瀏覽器 2"></p>
<p>微軟近日宣布一項重大決策，將於2025年10月31日終止熱門的Microsoft Editor瀏覽器擴充套件。<content><span style="font-weight: 400;">記者孫敬／編譯</span></p>
<p><span style="font-weight: 400;">微軟近日宣布一項重大決策，將於2025年10月31日終止熱門的Microsoft Editor瀏覽器擴充套件，未來用戶將不再需要額外安裝，就能直接在Microsoft Edge原生校對工具中使用由AI驅動的寫作輔助功能。隨著新版本上線後，IT人員無需手動調整任何設定或群組原則物件（GPO），Edge內建的校對工具將會自動接管所有編輯器職責。</span></p>
<p><b>延伸閱讀：<span style="color: #33cccc;"><a style="color: #33cccc;" href="https://www.technice.com.tw/techmanage/infosecurity/190415/" target="_blank" rel="noopener">Google反壟斷案獲歷史性勝利！法官裁定無需拆分Chrome與Android</a></span></b></p>
<p>[caption id="attachment_190450" align="aligncenter" width="1280"]<img class="wp-image-190450 size-full" src="https://www.technice.com.tw/wp-content/uploads/2025/09/Microsoft-Editor.jpg" alt="" width="1280" height="800" /> Microsoft Editor瀏擴充套件的功能將被AI取代。（圖／Microsoft Editor）[/caption]</p>
<h2><b>微軟告別擴充套件時代，AI功能將全面內建</b></h2>
<p><span style="font-weight: 400;">過往透過擴充套件提供的進階功能，例如即時語法分析、情境式風格檢查以及由AI驅動的重寫建議等，未來都將直接嵌入Edge的校對引擎中，並運用瀏覽器內建的自然語言處理（NLP）與機器學習模型來執行。</span></p>
<p><span style="font-weight: 400;">在擴充套件除役之前，仍可繼續使用擴充套件。在此之後，所有拼字檢查、文法修正與寫作建議等功能，都將直接整合在Edge的「語言與校對」設定中。微軟鼓勵用戶盡快熟悉這個全新的UI介面，包含可調整AI建議、自訂字典與檢視修改歷史等選項，讓寫作輔助變得更有效率。</span></p>
<p><span style="font-weight: 400;">這次更新是為了將AI服務統一整合至核心應用程式中，減少軟體碎片化，並簡化更新流程。透過將編輯器功能內建於Edge，微軟希望提供更流暢、高效能且安全的寫作輔助，而不再需要仰賴獨立的瀏覽器外掛。</span></p>
<p><span style="font-weight: 400;">資料來源：<span style="color: #33cccc;"><a style="color: #33cccc;" href="https://cybersecuritynews.com/microsoft-to-kill-poplar-editor-browser-extensions/" target="_blank" rel="noopener">Cyber Security News</a></span></span></content></p>
<p>這篇文章 <a rel="nofollow" href="https://www.technice.com.tw/techmanage/infosecurity/190429/">微軟宣布Microsoft Editor將於10月底退役 功能將內建於Edge瀏覽器</a> 最早出現於 <a rel="nofollow" href="https://www.technice.com.tw">科技島-掌握科技新聞、科技職場最新資訊</a>。</p>
]]></description>
		
					<wfw:commentRss>https://www.technice.com.tw/techmanage/infosecurity/190429/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Chrome擴充功能潛藏資安陷阱！受影響的範圍一次看</title>
		<link>https://www.technice.com.tw/techmanage/infosecurity/176172/</link>
					<comments>https://www.technice.com.tw/techmanage/infosecurity/176172/#respond</comments>
		
		<dc:creator><![CDATA[孫敬]]></dc:creator>
		<pubDate>Fri, 06 Jun 2025 10:23:16 +0000</pubDate>
				<category><![CDATA[資安]]></category>
		<category><![CDATA[生活]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[擴充功能]]></category>
		<guid isPermaLink="false">https://www.technice.com.tw/?p=176172</guid>

					<description><![CDATA[<p><img width="1200" height="627" src="https://www.technice.com.tw/wp-content/uploads/2024/01/131859466_fb-link_normal_none_0.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Google Chrome" decoding="async" srcset="https://www.technice.com.tw/wp-content/uploads/2024/01/131859466_fb-link_normal_none_0.jpg 1200w, https://www.technice.com.tw/wp-content/uploads/2024/01/131859466_fb-link_normal_none_0-300x157.jpg 300w, https://www.technice.com.tw/wp-content/uploads/2024/01/131859466_fb-link_normal_none_0-1024x535.jpg 1024w, https://www.technice.com.tw/wp-content/uploads/2024/01/131859466_fb-link_normal_none_0-768x401.jpg 768w" sizes="(max-width: 1200px) 100vw, 1200px" title="Chrome擴充功能潛藏資安陷阱！受影響的範圍一次看 3"></p>
<p>賽門鐵克近日發出警告，指出數款廣受用戶青睞的Google Chrome瀏覽器擴充功能，存在著資安漏洞。<content><span style="font-weight: 400;">記者孫敬／編譯<br />
</span><span style="font-weight: 400;"><br />
</span><span style="font-weight: 400;">根據外媒<a href="https://thehackernews.com/2025/06/popular-chrome-extensions-leak-api-keys.html" target="_blank" rel="noopener">報導</a>，全球資安研究公司Symantec（賽門鐵克）近日發出警告，指出數款廣受用戶青睞的Google Chrome瀏覽器擴充功能，存在著資安漏洞，而這些漏洞主要分為兩大類：透過未加密的HTTP連線傳輸敏感數據，以及在JavaScript程式碼嵌入了關鍵的機密金鑰。</span></p>
<p><b>延伸閱讀：<a href="https://www.technice.com.tw/techmanage/infosecurity/175896/" target="_blank" rel="noopener">微軟推出全新「歐洲安全計畫」 結合AI共享威脅情報強化資安</a></b></p>
<p><img class="aligncenter size-full wp-image-77364" src="https://www.technice.com.tw/wp-content/uploads/2023/10/131859466_fb-link_normal_none_0.jpg" alt="" width="1200" height="627" /></p>
<h2><b>熱門Chrome擴充功能現資安漏洞，數據傳輸與機密金鑰存高風險</b></h2>
<p><span style="font-weight: 400;">賽門鐵克的安全研究員Yuanjing Guo表示，部分擴充功能在數據傳輸時，未能使用安全的HTTPS加密協定，仍採用傳統的HTTP。這使得用戶的瀏覽網域、機器識別碼、作業系統細節、使用分析數據，甚至是解除安裝資訊，都以明文形式在網路中傳輸。如此一來，數據極易受到「中間人攻擊」（AitM）的威脅，讓惡意份子在同一網路環境下（如公共Wi-Fi）輕易攔截、甚至竄改數據，可能導致嚴重後果。</span></p>
<p><span style="font-weight: 400;">受影響的擴充功能包括：SEMRush Rank、PI Rank、Browsec VPN、MSN New Tab、MSN Homepage, Bing Search &amp; News。特別值得注意的是，DualSafe Password Manager &amp; Digital Vault這款密碼管理器，儘管未直接洩露用戶密碼，其遙測數據卻透過未加密的HTTP傳輸，嚴重損害了其作為安全工具的信任度。</span></p>
<h2><b>程式碼硬編碼機密金鑰，潛在攻擊面擴大</b></h2>
<p><span style="font-weight: 400;">除了未加密數據傳輸，賽門鐵克還發現另一類擴充功能存在更嚴重的漏洞：它們直接將API金鑰、機密和代幣等敏感資訊寫死（Hard-coded）在JavaScript程式碼中，攻擊者可依此送出惡意請求並執行多種攻擊行為。</span></p>
<p><span style="font-weight: 400;">這類漏洞可能造成的潛在風險包括：</span></p>
<ul>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">服務濫用與成本暴增： 攻擊者可利用外洩的GA4 API金鑰（如 Online Security &amp; Privacy extension、AVG Online Security 等）進行攻擊；或利用Azure語音辨識API金鑰（如 Equatio – Math Made Digital）消耗開發者的服務額度或增加成本。</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">非法訪問與內容上傳： 某些擴充功能（如Awesome Screen Recorder &amp; Screenshot和Scrolling Screenshot Tool &amp; Screen Capture）暴露了AWS存取金鑰，可能導致攻擊者未經授權訪問雲端儲存空間。</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">用戶數據追蹤與模擬交易： Microsoft Editor遭爆出遠端遙控金鑰；Trust Wallet則流出了Web3平台Ramp Network的API金鑰，恐被用於模擬加密貨幣交易訂單。</span></li>
<li style="font-weight: 400;" aria-level="1"><span style="font-weight: 400;">第三方函式庫連帶風險： Antidote Connector 等擴充功能使用的InboxSDK函式庫，也含有硬編碼憑證，且有超過90個擴充功能使用此函式庫，風險影響範圍廣泛。</span></li>
</ul>
<p></content></p>
<p>這篇文章 <a rel="nofollow" href="https://www.technice.com.tw/techmanage/infosecurity/176172/">Chrome擴充功能潛藏資安陷阱！受影響的範圍一次看</a> 最早出現於 <a rel="nofollow" href="https://www.technice.com.tw">科技島-掌握科技新聞、科技職場最新資訊</a>。</p>
]]></description>
		
					<wfw:commentRss>https://www.technice.com.tw/techmanage/infosecurity/176172/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
