Other nomination
The world of Site Isolation and compromised renderer
Assuming a compromised Chrome renderer, the slides find browser-process trust gaps in postMessage, protocol handlers, Reader mode, and extension message channels. Chained with permissive extension APIs, these gaps enable cross-site data reads, arbitrary file-URL access, credential theft, CSP bypass, and broader Site Isolation escapes.
Record
- Researcher
- Jun Kokatsu
- Published by
- Speaker Deck
- Date
- Format
- Recording
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Jun Kokatsu, first published at the original source. Preserved copies are kept so the citation survives its host.