Issue metadata
Sign in to add a comment
|
Security: It is possible to bypass an extension on the Chrome Web Store being blocked by an administrator
Reported by
jo...@slackorama.com,
Jun 13 2018
|
||||||||||||||||||||||
Issue descriptionVULNERABILITY DETAILS It is possible to download an extension that an administrator has blocked by getting the extension’s .CRX, extracting it, and loading it manually. VERSION Chrome Version: 67.0.3396.87, stable Operating System: ChromeOS, 67.0.3396.87 REPRODUCTION CASE It is impossible for me to provide a file to recreate the results, but I will tell you how i did it. First, I downloaded the .CRX file of the extension I wanted to use. Then, I extracted the extension’s contents from the .CRX file. Finally, I loaded that as an unpacked extension in chrome://extensions.
,
Jun 13 2018
Thanks for your report. This is certainly something that an administrator could block by using an extension whitelist instead of a blacklist. I'm not sure if this is a security property that ChromeOS makes guarantees about, so adding some CrOS people.
,
Jun 13 2018
If you want to prevent users from loading arbitrary extensions, you can either restrict the list of allowed extensions to only those within an allowlist, as wfh mentioned [1], or you can also disable developer tools (preventing users from loading unpacked extensions) [2]. I think either of those would solve the problem. I don't see this as being a security issue. I'll let kerrnel@ chime in, but I think we can probably close this out. +atwilson@ as well in case he has thoughts. [1] https://www.chromium.org/administrators/policy-list-3#ExtensionInstallWhitelist [2] https://www.chromium.org/administrators/policy-list-3#DeveloperToolsDisabled
,
Jun 13 2018
Good point. I didn’t consider that.
,
Jun 13 2018
yup, sounds like the enterprise policies have this one covered. I'll close this out tomorrow.
,
Jun 14 2018
The NextAction date has arrived: 2018-06-14
,
Jun 14 2018
Agreed. Canonically, admins that care about what extensions their users use should just enforce a whitelist. There's literally nothing stopping an extension author from putting multiple clones of their extension on the chrome web store, so blocking developer tools + individual extension IDs is insufficient.
,
Sep 20
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 Deleted