2 ms·
Chrome extensions are "sandboxed" in the sense that only the extension code has access to the special APIs behind special permissions. If they just inject some
by lumpio- 9y ago
Chrome extensions are "sandboxed" in the sense that only the extension code has access to the special APIs behind special permissions. If they just inject some ads onto a page, they won't have access to the extension APIs (they do naturally have access to everything on the page itself, which is why it's still a bad thing).
It would take a reasonable amount of stupidity to manage to download untrusted code and run it in a context that has access to the extension APIs if all you wanted to do is inject ads onto webpages. But no amount of sandboxing is going to stop that, if you give the code the permissions it wants. That's why one should always evaluate both the trustworthiness and competence of the developer before granting them scary permissions.
- Sironfoot 9y agoTrouble is the developer seems competent enough, and "Web Developer" is a popular, well-loved Chrome extension. Apparently he fell for a phishing attack https://twitter.com/chrispederick/status/892786731564417024 https://twitter.com/chrispederick/status/892786731564417024 I guess it can happen to anyone.