web analytics

Escaping well-configured VSCode extensions (for profit)

Rate this post

By Vasco Franco In part one of this two-part series, we escaped Webviews in real-world misconfigured VSCode extensions. But can we still escape extensions if they are well-configured? In this post, we’ll demonstrate how I bypassed a Webview’s localResourceRoots by exploiting small URL parsing differences between the browser—i.e., the Electron-created Chromium instance where VSCode and […]

The post Escaping well-configured VSCode extensions (for profit) appeared first on Security Boulevard.

Read MoreSecurity Boulevard

Views: 0

LinkedIn
Twitter
Facebook
WhatsApp
Email

advisor pick´S post

More Latest Published Posts