Collected research
Universal Code Execution by Chaining Messages in Browser Extensions
Browser extensions that inject content scripts on every origin and forward unvalidated window messages let a hostile page reach the extension's background script by postMessage, and through native messaging the desktop application behind it. Two disclosed cases show cross-origin cookie theft and a DLL load path controlled from the page, yielding code execution. The pattern is found at scale by querying an extension manifest dataset and taint-matching content scripts.
Record
- Published by
- spaceraccoon.dev
- Date
- Topic
- Browser
In the archive
Related sources
- PostMessage Security in Chrome Extensions Whitepaper
Tags
This page is the archive's own catalogue record. The research is the work of spaceraccoon.dev, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .