writeups.xyz writeups.xyz / Browser Extension Hacking

Title Vulnerabilities Programs Authors
Universal Code Execution by Chaining Messages in Browser Extensions
“MyFlaw” — Cross Platform 0-Day RCE Vulnerability Discovered in Opera’s Browser
Party time: Injecting code into Teleparty extension
Yes, fun browser extensions can have vulnerabilities too!
Steam, Fire, and Paste – A Story of UXSS via DOM-XSS & Clickjacking in Steam Inventory Helper
Reading Your Emails With A Read&Write Chrome Extension Same Origin Policy Bypass (~8 Million Users Affected)