|
|
|
|
|
by tyingq
3262 days ago
|
|
Since extensions can inject arbitrary js, there isn't really a way to be that granular. You could, for example, exfiltrate data by injecting an image tag with some extra url parameters on the url. Doesn't have to be xhr or websockets. |
|
"Send and receive data from anywhere on the internet"
Image doesn't load if you don't accept. Same goes for any tag or function that accesses external URI's.