4 ms·
I think the point is that this would run in a document belonging to the LastPass extension -- not that it would run in javascript injected into the target site.
by JackC 10y ago
I think the point is that this would run in a document belonging to the LastPass extension -- not that it would run in javascript injected into the target site.
The same attack you describe could be applied to basically any javascript you cared to write (say, String.prototype.length). The safest approach is to treat the output of injected javascript as untrusted third-party input to your extension code and work from there.