Chrome extensions with 10M+ devices are actively vulnerable to UXSS and UXSG (rebora.io) 9 points by galwm 3mo ago ↗ HN
[–] tsuberim 3mo ago ↗ Alarming. Same origin policy not strong enough. I suppose a lot of extensions may be similarly vulnerable.
2 comments
[ 0.25 ms ] story [ 30.6 ms ] thread