Other nomination
Universal Code Execution by Chaining Messages in Browser Extensions
Browser extensions that inject content scripts on every origin and forward unvalidated window messages let a hostile page reach the extension's background script by postMessage, and through native messaging the desktop application behind it. Two disclosed cases show cross-origin cookie theft and a DLL load path controlled from the page, yielding code execution. The pattern is found at scale by querying an extension manifest dataset and taint-matching content scripts.
Record
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.