Collected research
Spook.js: Attacking Chrome Strict Site Isolation via Speculative Execution
Spook.js
A Spectre-style transient execution attack that defeats Chrome Strict Site Isolation. Because Chrome groups pages by eTLD+1, an attacker-controlled subdomain can share a process with a sensitive page, and a type confusion then escapes the 32-bit sandbox to read the whole address space, recovering open tabs, autofilled passwords and credential-manager extension data.
Record
- Document
- Spook.js
- Researcher
- Ayush Agarwal, Sioli O'Connell, Jason Kim, Shaked Yehezkel, Daniel Genkin, Eyal Ronen and Yuval Yarom
- Published by
- spookjs.com
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Ayush Agarwal, Sioli O'Connell, Jason Kim, Shaked Yehezkel, Daniel Genkin, Eyal Ronen and Yuval Yarom, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .