TE
테크에코
홈24시간 인기최신베스트질문쇼채용
GitHubTwitter
홈

테크에코

Next.js로 구축된 기술 뉴스 플랫폼으로 글로벌 기술 뉴스와 토론을 제공합니다.

GitHubTwitter

홈

홈최신베스트질문쇼채용

리소스

HackerNews API원본 HackerNewsNext.js

© 2025 테크에코. 모든 권리 보유.

A privilege escalation from Chrome extensions (2023)

66 포인트작성자: deryilz2일 전

4 comments

Briannaj2일 전
This is worth more than 10k imo. But I guess since you have to have an extension installed maybe that's why?
评论 #44112294 未加载
评论 #44112495 未加载
tim19942일 전
Interesting read for sure! This is about ChromeOS though, Chrome on other platforms was not affected.
rxliuli2일 전
Your journey of discovery is really cool.
rvz2일 전
&gt; For example, Google awarded $10,000 to a bug report which showed that extensions could read local files by screenshotting them. But there are more dangerous things than file reads.<p>I think this researcher got scammed without knowing it.<p>Google paid $10k for this bug despite billions of users using Chrome and there are plenty of brokers that will pay much more than that. (e.g. Zerodium)<p>They should have sold it as a 0day on the black market for more that $250k.
评论 #44114776 未加载