Web Hack List

Collected research

A Security Study about Electron Applications and a Programming Methodology to Tame DOM Functionalities

Real-world Electron desktop apps inherit web injection bugs, letting attacker-supplied content reach DOM sinks and escalate into local-machine exploitation. The authors report vulnerabilities confirmed by vendors and propose DOM-tree type, a specification of the DOM shapes an app expects, enforced inside the Electron platform so an exploit surfaces as a type violation.

Record

Researcher
Zihao Jin, Shuo Chen, Yang Chen, Haixin Duan, Jianjun Chen and Jianping Wu
Published by
NDSS Symposium
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Zihao Jin, Shuo Chen, Yang Chen, Haixin Duan, Jianjun Chen and Jianping Wu, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .