Web Hack List

Collected research

CrossFire: An Analysis of Firefox Extension-Reuse Vulnerabilities

Legacy Firefox extensions share one JavaScript namespace, so an add-on can invoke the privileged XPCOM functionality of another. The paper names the resulting extension-reuse vulnerability: a malicious add-on making no sensitive API calls itself borrows capabilities leaked by benign extensions, evading manual vetting. CrossFire, a static analyser, locates such capability leaks and emits proof-of-concept exploits; the most popular extensions proved widely affected.

Record

Researcher
Ahmet Salih Buyukkayhan, Kaan Onarlioglu, William Robertson and Engin Kirda
Published by
ndss-symposium.org
Format
Whitepaper
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Ahmet Salih Buyukkayhan, Kaan Onarlioglu, William Robertson and Engin Kirda, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .