|
Google Chrome contains a flaw in the extensions handling that is triggered when handling handling of JavaScript URIs in tabs API. With a specially crafted Chrome Extension (CRX) file, a context-dependent attacker can bypass extension manifest permission restrictions and access content from arbitrary domains, local files, and DOM UI functionality.
|