Web Hack List

Later archive addition

CrossFire: An Analysis of Firefox Extension-Reuse Vulnerabilities

Legacy Firefox extensions share one JavaScript namespace, so an add-on can invoke the privileged XPCOM functionality of another. The paper names the resulting extension-reuse vulnerability: a malicious add-on making no sensitive API calls itself borrows capabilities leaked by benign extensions, evading manual vetting. CrossFire, a static analyser, locates such capability leaks and emits proof-of-concept exploits; the most popular extensions proved widely affected.

Record

Researcher
Ahmet Salih Buyukkayhan, Kaan Onarlioglu, William Robertson and Engin Kirda
Format
Whitepaper

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Ahmet Salih Buyukkayhan, Kaan Onarlioglu, William Robertson and Engin Kirda, first published at the original source. Preserved copies are kept so the citation survives its host.