|
Google Chrome contains a flaw as the webRequest API receives certain requests made by https://chrome.google.com/webstore/. With a specially crafted extension, a context-dependent attacker can intercept requests and execute script code in the context of the Web Store page e.g. causing it to install whitelisted extensions, display nag screens, and potentially use it as a stepping stone for a sandbox bypass.
|