4 ms·
We've introduced a new manifest version attribute in the extension manifest in Chrome 18 (currently in beta). When a developer updates his or her extension to u
by capo 15y ago
We've introduced a new manifest version attribute in the extension manifest in Chrome 18 (currently in beta). When a developer updates his or her extension to use manifest_version 2, Chrome will enforce the following CSP policy by default:
script-src 'self'; object-src 'self'
This policy imposes the following restrictions on extensions:
Extensions can no longer use inline scripts, such as <script> ... </script>. Instead, extensions must use out-of-line scripts loaded from within their package, such as <script src="foo.js"></script>.
Extensions can no longer use eval(). Note: If you’re using eval to parse JSON today, we suggest using JSON.parse instead.
Extensions can load plug-ins, such as SWF files, only from within their package or from a whitelist of HTTPS hosts.
http://blog.chromium.org/2012/02/more-secure-extensions-by-default.html http://blog.chromium.org/2012/02/more-secure-extensions-by-d...
- benmccann 15y agoI replied to your comment below (where you said the same thing), but it's not clear to me that CSP changes anything.
- aboodman 15y agoThe CSP changes primarily address the XSS issue in extensions. Many of these vulnerabilities come because extension developers run code from untrusted sources. CSP blocks that in most cases. Separately, we implemented web_accessible_resources. That addresses the sniffing issues.