Collected research
Kicking the Rims - A Guide for Securely Writing and Auditing Chrome Extensions
Kicking the Rims – A Guide for Securely Writing and Auditing Chrome Extensions
A guide to how Chrome extensions divide privilege between content scripts, background pages and isolated worlds, and to the anti-patterns that let a hostile web page cross that boundary: weak postMessage origin checks, DOM XSS reaching privileged APIs, loose externally_connectable rules and clickjackable web-accessible pages. It also releases tarnish, an automated extension auditor.
Record
- Document
- Kicking the Rims – A Guide for Securely Writing and Auditing Chrome Extensions
- Researcher
- Matthew Bryant
- Published by
- The Hacker Blog
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Matthew Bryant, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .