Hacker News new | ask | show | jobs
by somehnacct3757 1391 days ago
You will bypass the permission auth dialog, which is your last official chance to see what the code you're about to execute has access to.

The extension developer could add a malicious permission + new code to exploit it and it would look the same as using developer mode to add a Hello World extension