How Malicious extensions hide running arbitrary code
palant.info
palant.info
[
// Call console.log
"@", [".", ["console"], "log"],
// Verbatim call parameter
"hi"
]
What sort of sandboxing model is susceptible to this?I can't imagine any sort of principled sandboxing model that would be susceptible to running a whole interpreter within. Protections should go on the equivalent of syscalls, the side-effects code can have. We've known this for -- conservatively -- 30 years. Can somebody with knowledge explain how these extensions are breaking Chrome's security sandbox?
People over-pemission chrome extensions all the time, so you can execute arbitrary JS on any site you want once the user clicks ok. Why bother finding security sandbox exploits when users hand you the keys without thinking.
The extension platform is trying to further isolate extensions, but Google's profit motive is in its own way. See: MV3 and the response.
If Chrome offered an ad-blocker built in to the browser -- and maybe a privacy-blocker too -- they could eliminate the entire extension platform and solve the problem.
However as it is a commercial company and free product, not sure what are the tradeoffs for using Opera.
Yes, extension privileges are creepy and an ad blocker (ublock origin only, to be exactly) is the only extension I intentionally allow to act on all websites on my behalf. Which is a conscious tradeoff.
There are other useful extensions though, and I'd prefer a common permission architecture with frequent prompts to the current take-it-or-leave approach.
We aren’t talking about breaking out of the sandbox here, the extension sandbox stays intact. The problem is that this sandbox has plenty of privileges. And so Chrome attempts to restrict what code runs in this sandbox.
Technically speaking, they succeed – only the extension’s own code runs inside the sandbox here. But this is a mechanism aimed at preventing security vulnerabilities, not at combating outright malicious extensions. An extension can always download some data guiding its decisions. These extensions take it to the extreme, essentially turning that data into code.