Web Hack List

Collected research

The world of Site Isolation and compromised renderer

Shows what an attacker who has already compromised a Chrome renderer process can still reach despite Site Isolation: spoofed-origin postMessage steals PDF text, registerProtocolHandler and Reader mode enforce their checks only in the renderer, and extension message listeners answer content scripts. Chained, these read cross-site data, open arbitrary file URLs and bypass CSP.

Record

Researcher
Jun Kokatsu
Published by
Speaker Deck
Date
Format
Recording
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Jun Kokatsu, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .