Collected research
CrossFire: An Analysis of Firefox Extension-Reuse Vulnerabilities
Legacy Firefox extensions share one JavaScript namespace, so an add-on can invoke the privileged XPCOM functionality of another. The paper names the resulting extension-reuse vulnerability: a malicious add-on making no sensitive API calls itself borrows capabilities leaked by benign extensions, evading manual vetting. CrossFire, a static analyser, locates such capability leaks and emits proof-of-concept exploits; the most popular extensions proved widely affected.
Record
- Researcher
- Ahmet Salih Buyukkayhan, Kaan Onarlioglu, William Robertson and Engin Kirda
- Published by
- ndss-symposium.org
- Format
- Whitepaper
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Ahmet Salih Buyukkayhan, Kaan Onarlioglu, William Robertson and Engin Kirda, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .