Skip to content
Pixel Perfect Extension Abuse Enables Covert Script Injection and Security Header Removal

Pixel Perfect Extension Abuse Enables Covert Script Injection and Security Header Removal

Cybersecuritynews •Tushar Subhra Dutta • March 2, 2026

A browser extension that once earned a Featured badge from Google quietly turned into a remote code execution tool after its ownership changed hands, exposing thousands of users to covert script injection and full browser security header stripping. The campaign, centered on a legitimate-looking Google Lens wrapper called QuickLens, highlights how even a well-reviewed, functional […]

Extracted Entities

Attack Types (1)

Tools (1)