Web Hack List

Collected research

Extending a Hand to Attackers: Browser Privilege Escalation Attacks via Extensions

Shows the browser extension architecture imposes security requirements developers struggle to meet, so the boundary between a privileged extension component and its page-facing content script can be crossed. Fifty-nine flaws across forty extensions allowed universal cross-site scripting and theft of passwords or cryptocurrency. A process-isolation redesign is proposed as the fix.

Record

Researcher
Young Min Kim and Byoungyoung Lee
Published by
usenix.org
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Young Min Kim and Byoungyoung Lee, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .