3 ms·
> Chrome team has tried to make some changes to improve the situation The remote code execution ("RCE") capability requested by the extensions is programmatica
by gorhill 6y ago
> Chrome team has tried to make some changes to improve the situation
The remote code execution ("RCE") capability requested by the extensions is programmatically detectable by simply looking up the `content_security_policy` key in their manifest (which is JSON format).
The extensions had the following `content_security_policy` in their manifest:
script-src 'self' https://fly-analytics.com;
The best change the CWS can do to improve the situation is to forbid RCE capability the first place -- such capability means that it's impossible to code review such extensions and conclude they are safe.
Mozilla's policy is no-RCE allowed. I didn't try but I believe Mozilla's extension validator would programmatically reject any extension which asks for RCE through a manifest's `content_security_policy`.
- quotemstr 6y agoWon't help. You can always execute "code" if you try hard enough. Not all "code" is in the form of some JS file loaded into the extension context: it can be any custom sequence of instructions. There is no way to distinguish code from data.