Chrome extensions can access a lot of a user’s data: cookies and tokens, downloads, and anything you view or bookmark in Chrome, to name just a few. This makes for fertile ground for bug bounties, particularly as the Chrome API scopes can be so broad that developers sometimes open the door to permissions they didn’t intend to grant. We’ll look at how to do effective code reviews on Chrome extensions, what tools you can use to perform them, and some common tells of security issues. We’ll start with what the manifest.json file and its included permissions can tell us, before diving into how to spot three common insecure coding conventions in these extensions and what security issues they can create.
Breanne Boland is an application security engineer with the Enterprise Security Applications team at Salesforce. Before moving into appsec, she was a site reliability engineer and an infrastructure engineer, working in healthcare and govtech. Prior to that, she was a professional writer, and she still considers finishing the docs the real sign that the work is done. She writes fiction and zines, embroiders, makes creatures out of clay, and reminisces about traveling. She lives in Oakland and can be found at twitter.com/breanneboland.
Recorded at #Levelup0x07 22 Aug, 2020.
Presented by Bugcrowd.
Follow Breanne: twitter.com/BreanneBoland
Sign up on Bugcrowd: https://www.bugcrowd.com/
Join the conversation: https://discord.levelup.sh.
Follow Bugcrowd: http://twittter.com/Bugcrowd