Top 10 winner
Chrome addon hacking
Cross-scheme loading between http(s) pages and chrome-extension:// URLs is not fully isolated. Pointing a script element at chrome-extension://<id>/manifest.json and watching whether onload or onerror fires reveals whether that extension is installed, letting a page enumerate a visitor's Chrome add-ons in milliseconds from a list of popular IDs for fingerprinting or targeting.
Record
- Published by
- blog.kotowicz.net
In the archive
Related sources
- Chrome addons hacking: want XSS on google.com?
- Chrome addons hacking: Bye Bye AdBlock filters!
- XSS ChEF - Chrome extension exploitation framework
- Owning a system through a Chrome extension
- Fingerprinting demonstration
- Companion source and examples
- Companion exploitation framework
Tags
This page is the archive's own catalogue record. The research is the work of blog.kotowicz.net, first published at the original source. Preserved copies are kept so the citation survives its host.