#browserExtensionSecurity

iam-py-test :unverified:iampytest1@infosec.exchange
2024-06-28

According to @ajayyy, the maintainer of SponsorBlock, typing "uBlock" into the Chrome Web Store search directs users to "uBlock" instead of uBlock Origin.
Actually searching returns both extensions.
This is because Google no longer gives MV2 extensions "featured" status, which elevates them in search predictions.

github.com/uBlockOrigin/uBlock

#uBlockOrigin #uBlock #mv3 #chromeWebstore #browserExtensionSecurity

iam-py-test :unverified:iampytest1@infosec.exchange
2023-10-17

Be aware: in Chromium browsers, browser extension session storage is leaked into content script processes, and thus can be stolen by websites if they can compromise the content script.
The sky isn't falling, but something to be aware of.

bugs.chromium.org/p/chromium/i (from github.com/w3c/webextensions/i)

#browserextensionsecurity #chromiumsecurity

iam-py-test :unverified:iampytest1@infosec.exchange
2023-09-01

Just another reason to limit your browser extensions: vitonsky.net/blog/2023/09/01/m

Of course, it's hard to know if a developer will give in and include malware in their extension.

#browserextensionmalware #browserextensions #browserextensionsecurity

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst