Collected research
The world of Site Isolation and compromised renderer
Shows what an attacker who has already compromised a Chrome renderer process can still reach despite Site Isolation: spoofed-origin postMessage steals PDF text, registerProtocolHandler and Reader mode enforce their checks only in the renderer, and extension message listeners answer content scripts. Chained, these read cross-site data, open arbitrary file URLs and bypass CSP.
Record
- Researcher
- Jun Kokatsu
- Published by
- Speaker Deck
- Date
- Format
- Recording
- Topic
- Other
In the archive
Related sources
- The world of Site Isolation and compromised renderer Slides
- ChromeVox demonstration
- CSP bypass demonstration
- Adblock demonstration
Tags
This page is the archive's own catalogue record. The research is the work of Jun Kokatsu, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .