Collected research
Extending a Hand to Attackers: Browser Privilege Escalation Attacks via Extensions
Shows the browser extension architecture imposes security requirements developers struggle to meet, so the boundary between a privileged extension component and its page-facing content script can be crossed. Fifty-nine flaws across forty extensions allowed universal cross-site scripting and theft of passwords or cryptocurrency. A process-isolation redesign is proposed as the fix.
Record
- Researcher
- Young Min Kim and Byoungyoung Lee
- Published by
- usenix.org
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Young Min Kim and Byoungyoung Lee, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .