Insecure extension messaging test page

This is a page to demonstrate various instances of insecure browser extension messaging that I’ve come across. Install one of the extensions and then click the corresponding button on the page to trigger the exploit.

Note: If this page is public, then the exploits should be fixed in released extension versions. Take care to install a vulnerable version of the extension if you want to see the exploits in action.

Extensions

Browser extension Versions Description Trigger
DuckDuckGo Privacy Essentials (Chrome MV2 extension) 2022.11.23.1, 2022.12.1 (on page load) 2022.12.7, 2022.12.12 (on "Unblock Content" interaction) Website opens the extension options page and exfiltrates the user's "atb" value.

DuckDuckGo Privacy Essentials Results

Description Value
DuckDuckGo Privacy Essentials messaging secret Loading...
DuckDuckGo Privacy Essentials "atb" setting Loading...

Click to unblock...

It's a trap...