4 ms·
This is a good point and I haven’t read the manifest as I’m in a bit of a rush. Chrome did do a lot of work improving the manifest for conditions like this in v
by patrickhogan1 2y ago
This is a good point and I haven’t read the manifest as I’m in a bit of a rush. Chrome did do a lot of work improving the manifest for conditions like this in v3. I know with webRequest you have to specify urls but not sure if there is a separation of duties here in terms of
1. Permission to operate on any url page loaded locally and being able to modify the html/insert html like the clown image
2. Being able to webRequest http outbound to <any_url> where you could exfiltrate data.
I thought there was a way to insert html into any loaded page without having access to send outbound network requests.
If that is the case that it’s separate if the chrome extension were to be sold and the manifest were changed to allow nefarious behavior you would know.