Episode 95: Attacking Chrome Extensions with MatanBer - Big Impact on the Client-Side

Episode 95: Attacking Chrome Extensions with MatanBer - Big Impact on the Client-Side

Episode 95: In this episode of Critical Thinking - Bug Bounty Podcast In this episode, Justin is joined by MatanBer to delve into the intricacies of browser extensions. We talk about the structure and threat models, and cover things like service workers, extension pages, and isolated worlds.

Follow us on twitter at: @ctbbpodcast

We're new to this podcasting thing, so feel free to send us any feedback here: info@criticalthinkingpodcast.io

Shoutout to YTCracker for the awesome intro music!

------ Links ------

Follow your hosts Rhynorater & Teknogeek on twitter:

https://twitter.com/0xteknogeek

https://twitter.com/rhynorater

------ Ways to Support CTBBPodcast ------

Hop on the CTBB Discord at https://ctbb.show/discord!

We also do Discord subs at $25, $10, and $5 - premium subscribers get access to private masterclasses, exploits, tools, scripts, un-redacted bug reports, etc.

Today’s Sponsor - AssetNote. Listen to their podcast https://www.criticalthinkingpodcast.io/sspod

Today’s Guest: https://x.com/MtnBer

Resources

Universal Code Execution by Chaining Messages in Browser Extensions

https://spaceraccoon.dev/universal-code-execution-browser-extensions/

DOMLogger++

https://github.com/kevin-mizu/domloggerpp

BBRE Metamask bug

https://youtu.be/HnI0w156rtw?si=QixP8SX6JuRFz6PA

Bench Press: Leaking Text Nodes with CSS

https://blog.pspaul.de/posts/bench-press-leaking-text-nodes-with-css/

Timestamps:

(00:00:00) Introduction

(00:03:08) Structure & Threat Model for Browser Extension

(00:28:28) Extension Attack scenarios

(01:01:26) Attacking Extension Pages

(01:26:35) Attacking Service Workers

(01:46:23) Getting source code and dynamic debugging

Denne episoden er hentet fra en åpen RSS-feed og er ikke publisert av Podme. Den kan derfor inneholde annonser.

Episoder(189)

Episode 189: What Happened to HackerOne with Joel Margolis

Episode 189: What Happened to HackerOne with Joel Margolis

Episode 189: In this episode of Critical Thinking - Bug Bounty Podcast we’re (re)joined by none other than JOEL FREAKING MARGOLIS to talk about his blog post concerning HackerOne. We talk about what h...

27 Aug 1h 14min

Episode 188: DEFCON 34 Hotel Room Debrief

Episode 188: DEFCON 34 Hotel Room Debrief

Episode 188: In this episode of Critical Thinking - Bug Bounty Podcast Gr3pme and BusFactor grab some Hackers for a Live from DEFCON Episode to recap the event and highlight their top bugs and talks.F...

20 Aug 41min

Episode 187: Are Live Hacking Events even worth it?

Episode 187: Are Live Hacking Events even worth it?

Episode 187: In this episode of Critical Thinking - Bug Bounty Podcast we talk about how much to gaslight your Hackbot, finding “Internet Melting Bugs” and if LHEs still make sense in this AI age.Foll...

13 Aug 42min

Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?

Episode 186: Is Sol 5.6 SuperHuman for Bug Bounty?

Episode 186: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some Recent Bug Bounty trends and pricing changes, wp2Shell exploits, Sol 5.6, and prompting via the Gauntlet loop....

6 Aug 58min

Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026

Episode 185: Harley & Ariel - Your Guide to Bug Bounty Village 2026

Episode 185: In this episode of Critical Thinking - Bug Bounty Podcast we, It’s almost time for DEFCON! We’re joined by Harley Kimball and Ariel Garcia to preview this year’s Bug Bounty Village!Follow...

30 Jul 1h 23min

Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson)

Episode 184: 750+ Bugs in 2026 with 0xMoose (Ads Dawson)

Episode 184: In this episode of Critical Thinking - Bug Bounty Podcast we’re joined by Ads Dawson (0xMoose) to talk about his skyrocketing report velocity, as well as how he builds and manages his hac...

23 Jul 1h 13min

Episode 183: PortSwigger Research Impossible XSS SOLVED

Episode 183: PortSwigger Research Impossible XSS SOLVED

Episode 183: In this episode of Critical Thinking - Bug Bounty Podcast Justin and Brandyn talk about looking at AI features like tech features, Using AI to leak private repos, and solving PortSwigger’...

16 Jul 1h 14min

Episode 182: Partial Auth, Hackbot GraphQL, and AI's #1 Mission

Episode 182: Partial Auth, Hackbot GraphQL, and AI's #1 Mission

Episode 182: In this episode of Critical Thinking - Bug Bounty Podcast we talk about some recent bugs involving WPM, MCP, and a possible emerging bug class using Wayback. We also talk about some Graph...

9 Jul 39min

Populært innen Teknologi

lydartikler-fra-aftenposten
teknisk-sett
tomprat-med-gunnar-tjomlid
rss-kunstig-intelligens-med-elisabeth-maren-og-morten
nasjonal-sikkerhetsmyndighet-nsm
smart-forklart
energi-og-klima
rss-alt-som-gar-pa-strom
fornybaren
rss-snakk-om-sikkerhet
elektropodden
shifter
teknologi-og-mennesker
rss-ai-forklart
rss-ki-praten
rss-heis
pedagogisk-intelligens
rss-god-blanding
rss-alt-vi-kan
rss-bak-skyen