web-accessible-resources

1 article
sort: new top best
clear filter
0 8/10

Steam Inventory Helper Chrome extension v1.13.6 suffered from a DOM-based XSS in bookmarks.html combined with clickjacking via over-permissive web_accessible_resources, allowing arbitrary JavaScript execution in the extension's privileged context and hijacking of all authenticated websites. The vulnerability exploits jQuery's unsafe DOM manipulation APIs (html/append) paired with unsafe-eval CSP directive, weaponized through UI redressing to trick users into pasting XSS payloads.

Steam Inventory Helper Matthew Bryant Chrome
thehackerblog.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details