|
|
|
|
|
by dmalvarado
3263 days ago
|
|
Seems like there should be some additional protection in the extensions API, if there is not already. "Read and change all your data on the websites that you visit" vs. "And send it somewhere over the web" are two separate layers of permission. Footnote: I can't visit the page. Blocked by corporate. |
|
You could, for example, exfiltrate data by injecting an image tag with some extra url parameters on the url. Doesn't have to be xhr or websockets.