Typical severity: High. Likelihood of attack: Medium. An adversary directly installs or tricks a user into installing a malicious extension into existing trusted software, with the goal of achieving a variety of negative technical impacts.
Only install extensions/plugins from official/verifiable sources. | Confirm extensions/plugins are legitimate and not malware masquerading as a legitimate extension/plugin. | Ensure the underlying software leveraging the extension/plugin (including operating systems) is up-to-date. | Implement an extension/plugin allow list, based on the given security policy. | If applicable, confirm extensions/plugins are properly signed by the official developers.