Skip to content

Bridge: any installed extension can connect without the token via a chrome-extension:// Origin #108

Description

@chintoleung

Summary

BridgeServer.attach() (packages/browser/bridge-browser/src/server.ts, the loopbackNoToken branch) grants the loopback bearer-token exemption to every Origin that starts with chrome-extension:// — not just this extension. Any other installed extension can open a WebSocket to ws://127.0.0.1:<port>/ext/bridge, send a tokenless hello, and drive the browser_* tools.

Pages cannot forge an Origin header, but any extension can present its own chrome-extension://<id> Origin, so the prefix check is not an identity boundary between extensions.

Impact

A malicious/compromised co-installed extension gains unauthenticated access to the bridge (prompt/approval flows still apply, but the auth layer is bypassed). This becomes more relevant if #100 widens connect-src for remote bridges.

Suggested fix

  • Replace the prefix check with an exact-match allowlist of extension origins.
  • Ship a stable manifest key so this extension's Chromium id is deterministic (path-independent), and pin that single origin by default.
  • Keep the token path for everything else (Firefox moz-extension:// UUIDs, custom builds, non-loopback clients); make the list configurable for forks.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions