Later archive addition
Evernote WebClipper Universal XSS
The research finds a universal cross-site scripting flaw in the Evernote Web Clipper browser extension. Extension behavior and insufficient origin isolation let attacker-controlled page content execute with access to other web origins, demonstrating how a privileged extension can collapse normal browser security boundaries.
Record
- Researcher
- Adam Chester and @_xpn_
- Published by
- XPN Infosec Blog
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Adam Chester and @_xpn_, first published at the original source. Preserved copies are kept so the citation survives its host.