Web Hack List

Collected research

Kicking the Rims - A Guide for Securely Writing and Auditing Chrome Extensions

Kicking the Rims – A Guide for Securely Writing and Auditing Chrome Extensions

A guide to how Chrome extensions divide privilege between content scripts, background pages and isolated worlds, and to the anti-patterns that let a hostile web page cross that boundary: weak postMessage origin checks, DOM XSS reaching privileged APIs, loose externally_connectable rules and clickjackable web-accessible pages. It also releases tarnish, an automated extension auditor.

Record

Document
Kicking the Rims – A Guide for Securely Writing and Auditing Chrome Extensions
Researcher
Matthew Bryant
Published by
The Hacker Blog
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Matthew Bryant, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .