Collected research
A Security Study about Electron Applications and a Programming Methodology to Tame DOM Functionalities
Real-world Electron desktop apps inherit web injection bugs, letting attacker-supplied content reach DOM sinks and escalate into local-machine exploitation. The authors report vulnerabilities confirmed by vendors and propose DOM-tree type, a specification of the DOM shapes an app expects, enforced inside the Electron platform so an exploit surfaces as a type violation.
Record
- Researcher
- Zihao Jin, Shuo Chen, Yang Chen, Haixin Duan, Jianjun Chen and Jianping Wu
- Published by
- NDSS Symposium
- Topic
- Browser
In the archive
Related sources
- NDSS 2023 - A Security Study about Electron Applications and a Programming Methodology to Tame DOM..
- NDSS 2023 - A Security Study about Electron Applications and a Programming Methodology to Tame DOM..
Tags
This page is the archive's own catalogue record. The research is the work of Zihao Jin, Shuo Chen, Yang Chen, Haixin Duan, Jianjun Chen and Jianping Wu, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .