BlackTree Security · Infrastructure · Automation · AI

The Security Extension Could Send Your Browser Through an Attacker’s Server.

A browser extension installed to protect privileged access could be turned into the route toward attacker-controlled infrastructure.

Fortinet published advisory FG-IR-26-168 on 8 September with a CVSS score of 9.1. The company says improper authentication in the Fortinet Privileged Access Agent Chrome extension can let a remote unauthenticated attacker proxy a user’s browser traffic through attacker-controlled servers if the user visits a malicious website.

No malicious exploitation or public proof of concept was confirmed in the sources reviewed by BlackTree. The issue still deserves priority because it crosses the trust boundary around privileged browser sessions and can be triggered from web content.

The browser component is part of the privileged-access boundary

Privileged access management is often treated as a server-side control: a vault, broker, gateway or session manager stands between the administrator and the protected system. The browser extension is easy to see as a small client accessory.

In practice, the extension participates in the session. It can identify protected workflows, communicate with FortiPAM and influence how the browser reaches managed resources. A failure in that component can therefore redirect the very traffic the platform is meant to control.

Fortinet’s description requires the user to visit a malicious website, but it does not require the attacker to authenticate. That makes ordinary browsing on an administrative workstation part of the exposure path.

Proxying traffic is not automatically the same as decrypting it

Routing browser traffic through an attacker’s server can expose destinations, timing and unencrypted content. It may also create opportunities to block, redirect or manipulate sessions.

Fortinet’s public summary does not state that the flaw automatically defeats TLS, steals every credential or reads all protected traffic. Those outcomes depend on how the extension handles connections, certificates and application data. They should not be treated as confirmed without the technical details or a reproduction.

The supported conclusion is already serious: an unauthenticated remote party can influence the routing of a privileged user’s browser after a malicious-site visit.

The fix has two moving parts

Fortinet’s remediation pairs a supported FortiPAM release with a corrected Chrome extension. Customers should upgrade to FortiPAM 1.9.1 or 1.8.4, as applicable, and deploy Fortinet Privileged Access Agent extension version 8.0.1.123 or later.

Updating only the server can leave a vulnerable extension in browsers. Updating only the extension can create a version combination that has not been validated with the installed FortiPAM branch. The server and client inventory must be checked together.

Extension deployment also has its own delay. Browsers may wait for restart, devices may be offline and users may have locally installed copies outside enterprise policy. An approved extension version in the management console is not the same as a verified running version on every privileged workstation.

Administrative browsing deserves a smaller attack surface

A workstation used for privileged sessions should not also be the place where an administrator reads general email, follows unknown links and browses the open web. The malicious-site prerequisite makes that separation directly relevant.

Dedicated privileged-access workstations, restricted browsing policies and a tightly controlled extension allow-list reduce the chance that hostile content can reach the component. These controls do not replace the update. They reduce the surrounding opportunity for this and future client-side failures.

What FortiPAM customers should do

  • Inventory the FortiPAM server branch and every deployed Privileged Access Agent Chrome extension version.
  • Upgrade to FortiPAM 1.9.1 or 1.8.4, as applicable, and extension 8.0.1.123 or later.
  • Force or verify browser relaunch where required for the corrected extension to become active.
  • Remove unmanaged or duplicate copies of the extension and enforce the approved version through browser policy.
  • Restrict open-web browsing from privileged-access workstations and administrative browser profiles.
  • Review proxy configuration changes, extension events, unexpected destinations and unusual network paths from systems used for privileged sessions.
  • If suspicious routing occurred, investigate the affected sessions and protected accounts instead of assuming the extension update reverses earlier activity.

The BlackTree view

Security extensions inherit trust because they enforce policy, broker access or protect a sensitive workflow. That trust also makes their failures valuable. The extension is not outside the protected system. It is part of it.

The operational lesson is to manage privileged browser components like endpoint security agents: version them, restrict them, monitor them and test the whole server-client combination. A secure vault cannot compensate for a browser route that an attacker can bend.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *