Web Hack List

Top 10 winner

Chrome addon hacking

Intro to Chrome addons hacking: fingerprinting

Cross-scheme loading between http(s) pages and chrome-extension:// URLs is not fully isolated. Pointing a script element at chrome-extension://<id>/manifest.json and watching whether onload or onerror fires reveals whether that extension is installed, letting a page enumerate a visitor's Chrome add-ons in milliseconds from a list of popular IDs for fingerprinting or targeting.

Record

Document
Intro to Chrome addons hacking: fingerprinting
Published by
blog.kotowicz.net
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of blog.kotowicz.net, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .