Web Hack List

Later archive addition

Evernote WebClipper Universal XSS

The research finds a universal cross-site scripting flaw in the Evernote Web Clipper browser extension. Extension behavior and insufficient origin isolation let attacker-controlled page content execute with access to other web origins, demonstrating how a privileged extension can collapse normal browser security boundaries.

Record

Researcher
Adam Chester and @_xpn_
Published by
XPN Infosec Blog

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Adam Chester and @_xpn_, first published at the original source. Preserved copies are kept so the citation survives its host.