Tag: Manifest V3
-

The Stealth Oracle: How “Safe” Chrome Extensions Can Reconstruct Your Private URLs Character by Character
A sophisticated technique has been unearthed within Chrome that permits the exfiltration of the complete URL from any active tab, even by an extension explicitly denied access to tabs or website content. This vulnerability leverages the declarativeNetRequest permission—a mandate traditionally viewed as benign due to its focus on request filtering rather than direct DOM manipulation.…
-

Exposing the Invisible: Inspect Web Security with the Scrapfly Anti-bot Detector
Scrapfly Anti-bot Detector is a Manifest V3 Chrome extension that helps security researchers, web developers, and bot detection enthusiasts identify and analyze: CAPTCHAs: reCAPTCHA, hCaptcha, FunCaptcha, GeeTest, Cloudflare Turnstile Anti-bot systems: Cloudflare, Akamai, DataDome, PerimeterX, Shape Security, AWS WAF, Imperva, Kasada, and more Fingerprinting techniques: Canvas, WebGL, Audio, Font, WebRTC, Performance, Navigator, Storage, and other…
-

RedExt: New Red Team Tool Uses Chrome Extension for Covert Browser Data Exfiltration
RedExt is a sophisticated browser data analysis framework designed for authorized red team operations. It combines a Manifest V3 Chrome extension with a Flask-based C2 server to provide comprehensive browser data collection and analysis capabilities through a modern dark-themed dashboard. Features Cookie Extraction Domain-specific filtering Automatic cookie organization by domain Captures all cookie attributes Supports…
-
Firefox will support Manifest V3 extension specification
Mozilla posted that Firefox will implement the Manifest V3 extension specification of Google Chrome to maintain compatibility and support cross-browser development. The Manifest V3 extension specification was proposed by Google to enhance the security, privacy, and performance of the Chrome browser. Its contents include codes that no longer allow remote hosting and use the new…
