Web Hack List

Later archive addition

Spook.js: Attacking Chrome Strict Site Isolation via Speculative Execution

A Spectre-style transient execution attack that defeats Chrome Strict Site Isolation. Because Chrome groups pages by eTLD+1, an attacker-controlled subdomain can share a process with a sensitive page, and a type confusion then escapes the 32-bit sandbox to read the whole address space, recovering open tabs, autofilled passwords and credential-manager extension data.

Record

Researcher
Ayush Agarwal, Sioli O'Connell, Jason Kim, Shaked Yehezkel, Daniel Genkin, Eyal Ronen and Yuval Yarom

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Ayush Agarwal, Sioli O'Connell, Jason Kim, Shaked Yehezkel, Daniel Genkin, Eyal Ronen and Yuval Yarom, first published at the original source. Preserved copies are kept so the citation survives its host.