NoDAVG All articles
Investigative

The Add-On Attack Surface: How AV Plugin Ecosystems Became a Hacker's Welcome Mat

NoDAVG
The Add-On Attack Surface: How AV Plugin Ecosystems Became a Hacker's Welcome Mat

Photo: cybersecurity software plugin vulnerability hacker backdoor computer, via www.csoonline.com

There's a particular kind of irony that security researchers love to point out at conferences: the tool you installed to protect your system often ends up expanding its attack surface in ways you never agreed to. We've talked on this site before about real-time scanning traps, update pipeline vulnerabilities, and the permission overreach baked into most major AV products. But there's a quieter problem that's been festering in plain sight — one that doesn't make the vendor press releases and rarely shows up in independent lab tests.

We're talking about the plugin ecosystem. The add-ons. The browser extensions. The "enhanced protection" integrations that antivirus vendors either build themselves or happily wave through a vetting process so thin you could read through it.

And increasingly, that ecosystem is becoming one of the most reliable ways for threat actors to get a foothold on machines that are, on paper, fully protected.

How AV Platforms Became Plugin Marketplaces

Over the last decade, major security suites stopped being simple scan-and-quarantine tools. Products from the big names — Norton, McAfee, Bitdefender, Avast, and their extended families of sub-brands — evolved into full-blown security platforms. VPN integration, password managers, browser extensions for "safe browsing," parental controls, performance optimizers, identity monitoring dashboards. The list keeps growing.

Some of that functionality is built in-house. A lot of it isn't. Vendors partner with third-party developers, bundle external tools, or build open integration layers that allow outside software to hook into the core security product. From a business standpoint, it makes sense — you get to market a more feature-rich product without building everything from scratch.

From a security standpoint, you've just handed a set of skeleton keys to anyone who can compromise one of those third-party components.

The attack surface math here isn't complicated. If your AV product runs with elevated system privileges — and most of them do — then any plugin or integration that touches that product inherits a version of that access. Compromise the plugin, and you've potentially compromised something with near-root access to the host machine. That's not a theoretical concern. It's been demonstrated repeatedly in the wild.

Real-World Cases That Didn't Get Enough Attention

In 2020, researchers at Avast's own threat intelligence division — in a somewhat awkward piece of internal disclosure — confirmed that the Avast and AVG browser extensions had been used as a vector in a campaign dubbed Operation Goldfish. The extensions, which had tens of millions of installs across Chrome and Firefox, were found to be leaking sensitive browsing data. The underlying architecture that made that leak possible was the same architecture that a more aggressive actor could have weaponized for code execution.

Then there's the CCleaner incident, which at this point is practically a case study in supply chain compromise. Piriform, the company behind CCleaner, was acquired by Avast in 2017. Months later, the CCleaner binary itself — distributed through official channels and bundled with Avast's security ecosystem — was found to contain a backdoor implanted during the build process. Millions of machines downloaded what they believed was a trusted, security-adjacent tool. What they got was a two-stage malware payload targeting tech companies.

More recently, security firm SafeBreach published research in 2022 demonstrating that multiple major AV products could be abused through their own update and plugin mechanisms to load arbitrary unsigned code. The researchers didn't name every vendor affected, but the methodology they documented applied broadly across products that use side-loading patterns — which is most of them.

These aren't fringe cases. They're a pattern.

The Vetting Problem Nobody Wants to Own

Ask an AV vendor how they vet third-party integrations and you'll get a version of the same answer: we have a security review process, we require partners to meet certain standards, we monitor for anomalous behavior. What you won't get is a detailed breakdown of what that process actually looks like, how often it's applied to updates (not just initial submissions), or who's accountable when something slips through.

The browser extension space is particularly messy. Google and Mozilla both have review processes for extensions listed in their stores, but those processes are notoriously inconsistent and heavily automated. AV vendors that distribute browser extensions through those stores are subject to the same inadequate review pipeline as anyone else — which means an extension update that introduces malicious code can reach millions of users before anyone catches it.

And extension updates, unlike core application updates, often don't trigger the same level of user awareness or system-level scrutiny. You don't get a UAC prompt when your browser extension silently updates overnight. You don't get a changelog notification. It just happens.

The trust chain here is genuinely alarming when you map it out: you trust your AV vendor, your AV vendor trusts their third-party partners, those partners push updates through browser store infrastructure that trusts automated scanning over human review, and somewhere in that chain is a gap that a motivated threat actor can drive a truck through.

Why This Is Harder to Fix Than It Sounds

Vendors aren't oblivious to this problem. Several of them have tightened their internal development practices following high-profile incidents. But there are structural incentives that work against meaningful reform.

First, the competitive pressure to ship feature-rich products doesn't slow down just because the security review process needs more time. If your competitor bundles a password manager and you don't, you lose customers — regardless of whether that password manager was audited properly.

Second, third-party integrations are often negotiated at the business development level, not the security engineering level. By the time a security team gets to review a new partner integration, the contract is already signed and the launch date is already set.

Third — and this is the one that doesn't get said out loud enough — a lot of AV vendors have a vested interest in not drawing attention to the fact that their ecosystem has a large attack surface. Admitting that your plugin architecture is a potential liability is not great for sales.

What You Can Actually Do About It

The uncomfortable truth is that most users don't have visibility into which third-party components are bundled with their security software. You can dig into it — check your installed browser extensions, audit what's actually running on your system under the umbrella of your AV suite, and look up the parent company structures of any tools that got installed alongside your main product.

When it comes to browser extensions specifically: less is more. If your AV vendor pushed a browser extension during installation and you didn't explicitly choose to install it, it's worth asking whether you actually need it. The "safe browsing" protection most of those extensions offer is marginal at best, and the attack surface they introduce is real.

For IT teams managing endpoints across an organization, this is worth a formal policy conversation. Which AV integrations are actually required? Which ones are bundled defaults that nobody asked for? Reducing the number of third-party components touching your security stack is a legitimate risk reduction strategy, not paranoia.

The security industry spent years telling us to stop installing unnecessary software. It's time they applied that advice to themselves.

All Articles

Related Articles

Protected to Death: How Your Antivirus Turned Your PC Into a Paperweight

Protected to Death: How Your Antivirus Turned Your PC Into a Paperweight

Trusted by Design, Weaponized by Opportunity: The Dark Side of AV Update Pipelines

Trusted by Design, Weaponized by Opportunity: The Dark Side of AV Update Pipelines

Big Fish, Small Pond: How AV Industry Consolidation Is Making Everyone Less Safe

Big Fish, Small Pond: How AV Industry Consolidation Is Making Everyone Less Safe