Web Hack List

Collected research

Arc Browser UXSS, Local File Read, Arbitrary File Creation and Path Traversal to RCE

Arc's undocumented arc://boost/play/ endpoint builds and installs a browser extension from a compressed JSON blob in the URL. Permissions come from manifest.json while the install screen reads boost.config.json, so the prompt can promise a colour change on example.com while the manifest takes every URL and file:// - UXSS plus local file read. The per-file name and path are unchecked, so ../ writes a LaunchAgents plist that runs at login; an Easel embed frames the arc:// URL to deliver it.

Record

Researcher
Renwa and @RenwaX23
Published by
Medium
Date
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Renwa and @RenwaX23, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .