Web Hack List

Collected research

Piloting Edge Copilot

An attack chain against Edge's Copilot sidebar, whose internal WebUI holds privileged extension APIs and camera and microphone access while framing Bing. A postMessage listener assigning attacker data to an iframe src, and a pass-through Trusted Types policy rendering the page title as HTML, give script execution in the trusted frame; permission delegation then reaches the microphone. A hashchange command listener lets any page prompt Copilot and leak its memory via markdown links.

Record

Researcher
@speakerdeck and Jun Kokatsu
Published by
Speaker Deck
Date
Format
Slides
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of @speakerdeck and Jun Kokatsu, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .