Web Hack List

Other nomination

Read&Write Chrome Extension Same Origin Policy (SOP) Bypass Vulnerability

The Read&Write Chrome extension injected a content script into every page that relayed any postMessage to its privileged background page without checking the sender's origin. Any site could therefore call background methods such as thGetVoices, making the extension fetch an arbitrary URL with the victim's cookies and hand back the body, which reads a logged-in user's Gmail.

Record

Researcher
Matthew Bryant
Published by
The Hacker Blog

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Matthew Bryant, first published at the original source. Preserved copies are kept so the citation survives its host.