Top 10 winner
Chrome addon hacking
Intro to Chrome addons hacking: fingerprinting
Cross-scheme loading between http(s) pages and chrome-extension:// URLs is not fully isolated. Pointing a script element at chrome-extension://<id>/manifest.json and watching whether onload or onerror fires reveals whether that extension is installed, letting a page enumerate a visitor's Chrome add-ons in milliseconds from a list of popular IDs for fingerprinting or targeting.
Record
- Document
- Intro to Chrome addons hacking: fingerprinting
- Published by
- blog.kotowicz.net
- Topic
- Browser
In the archive
Related sources
- Chrome addons hacking: want XSS on google.com?
- Chrome addons hacking: Bye Bye AdBlock filters!
- XSS ChEF - Chrome extension exploitation framework
- Owning a system through a Chrome extension
- Chrome addons fingerprinting
- Chrome addons research examples
- XSS CheF
Tags
This page is the archive's own catalogue record. The research is the work of blog.kotowicz.net, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .