Web Hack List

Collected research

Read&Write Chrome Extension Same Origin Policy (SOP) Bypass Vulnerability

Reading Your Emails With A Read&Write Chrome Extension Same Origin Policy Bypass (~8 Million Users Affected)

The Read&Write Chrome extension injected a content script into every page that relayed any postMessage to its privileged background page without checking the sender's origin. Any site could therefore call background methods such as thGetVoices, making the extension fetch an arbitrary URL with the victim's cookies and hand back the body, which reads a logged-in user's Gmail.

Record

Document
Reading Your Emails With A Read&Write Chrome Extension Same Origin Policy Bypass (~8 Million Users Affected)
Researcher
Matthew Bryant
Published by
The Hacker Blog
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Matthew Bryant, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .