Web Hack List

Collected research

Attacking the DevTools

Guest Blog Post - Attacking the DevTools

Chromium's DevTools is a privileged page an extension can reach, through an unvalidated remoteBase parameter, a javascript: devtools_page entry, or crafted channel messages that overwrite the stored extension origin. Code running there reads local files, injects scripts into any site or extension, and drives the DevTools Protocol to escape the sandbox.

Record

Document
Guest Blog Post - Attacking the DevTools
Researcher
David Erceg
Published by
Microsoft Browser Vulnerability Research
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of David Erceg, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .