Collected research
Read&Write Chrome Extension Same Origin Policy (SOP) Bypass Vulnerability
Reading Your Emails With A Read&Write Chrome Extension Same Origin Policy Bypass (~8 Million Users Affected)
The Read&Write Chrome extension injected a content script into every page that relayed any postMessage to its privileged background page without checking the sender's origin. Any site could therefore call background methods such as thGetVoices, making the extension fetch an arbitrary URL with the victim's cookies and hand back the body, which reads a logged-in user's Gmail.
Record
- Document
- Reading Your Emails With A Read&Write Chrome Extension Same Origin Policy Bypass (~8 Million Users Affected)
- Researcher
- Matthew Bryant
- Published by
- The Hacker Blog
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Matthew Bryant, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .