A researcher disclosed a "universal code execution" attack pattern in browser extensions in which a malicious website sends crafted window.postMessage data to a content script that forwards it to a privileged extension background process. Extensions that inject content scripts broadly and fail to validate message origins can expose privileged capabilities to arbitrary websites, including cross-origin cookie access and same-origin policy bypasses.
The impact can escalate to operating-system command execution when the extension relays attacker-controlled data through Chrome native messaging to an unsafe native host. The researcher identified the pattern through extension-manifest analysis and Semgrep taint tracking, and reported two censored, allegedly unpatched cases affecting large user populations; one smart-card extension with roughly two million users reportedly allowed a malicious DLL to be loaded through path traversal in a PKCS#11 library path. Organizations should assess extensions for strict content-script scope, origin and schema validation on message-passing interfaces, and hardened native-message handling.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Arseny Reutov published prior work on relaying postMessage traffic through Chrome extensions toward native applications.
The researcher disclosed two vulnerabilities to the respective extension owners. The censored cases involved insecure content-script message forwarding that could enable cookie theft or, through native messaging and a path-traversal flaw, operating-system code execution.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
developer.chrome.com
Open sourcespaceraccoon.dev
Open sourcedeveloper.chrome.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.