Collected research
Attacking the DevTools
Guest Blog Post - Attacking the DevTools
Chromium's DevTools is a privileged page an extension can reach, through an unvalidated remoteBase parameter, a javascript: devtools_page entry, or crafted channel messages that overwrite the stored extension origin. Code running there reads local files, injects scripts into any site or extension, and drives the DevTools Protocol to escape the sandbox.
Record
- Document
- Guest Blog Post - Attacking the DevTools
- Researcher
- David Erceg
- Published by
- Microsoft Browser Vulnerability Research
- Date
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of David Erceg, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .