Web Hack List

Collected research

Universal Code Execution by Chaining Messages in Browser Extensions

Browser extensions that inject content scripts on every origin and forward unvalidated window messages let a hostile page reach the extension's background script by postMessage, and through native messaging the desktop application behind it. Two disclosed cases show cross-origin cookie theft and a DLL load path controlled from the page, yielding code execution. The pattern is found at scale by querying an extension manifest dataset and taint-matching content scripts.

Record

Published by
spaceraccoon.dev
Date
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of spaceraccoon.dev, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .