Later archive addition
Subverting Electron Apps via Insecure Preload
The article categorizes four ways Electron preload scripts can undermine renderer isolation, including leaked Node globals, dangerous exported functions, sandbox bypasses, and prototype tampering without context isolation. Wire and Discord case studies turn renderer code execution into arbitrary file writes or privileged IPC leading to native command execution.
Record
- Researcher
- Luca Carettoni
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Luca Carettoni, first published at the original source. Preserved copies are kept so the citation survives its host.