Hackers of India

Breaking Microsoft Edge extensions security policies

 Nikhil Mittal 

2019/05/21

Abstract

Browsers handle our private information. We use browser extensions on a daily-life basis—Adblock Plus, Grammarly, LastPass. When you install an extension that has permission to execute JavaScript code on https://www.bing.com, indeed it allows JavaScript code execution on https://mail.google.com. This means the extension can also read your Google mail, which violates user privacy and damage trust. The speaker will tell about a major flaw in Microsoft Edge that allowed an extension to read the user’s Google and Facebook data.

video removed