Charts
DataOn-chain
VIP
Market Cap
API
Rankings
CoinOSNew
CoinClaw🦞
Language
  • 简体中文
  • 繁体中文
  • English
Leader in global market data applications, committed to providing valuable information more efficiently.

Features

  • Real-time Data
  • Special Features
  • AI Grid

Services

  • News
  • Open Data(API)
  • Institutional Services

Downloads

  • Desktop
  • Android
  • iOS

Contact Us

  • Chat Room
  • Business Email
  • Official Email
  • Official Verification

Join Community

  • Telegram
  • Twitter
  • Discord

© Copyright 2013-2026. All rights reserved.

简体繁體English
|Legacy
BTCBTC
💲73084.76
-
1.38%
ETHETH
💲2275.53
-
2.33%
SOLSOL
💲92.28
-
1.6%
WLDWLD
💲0.3794
-
2.99%
USDCUSDC
💲0.9997
-
0.02%
XRPXRP
💲1.49
-
1.32%

Slow Mist Cosine: Attention should be paid to the permission application of browser extensions, while also having isolation thinking

PANews
PANews|3月 15, 2025 09:04
SlowMist Cosine has posted on X platform to remind the community of browser extension security issues. He stated that an extension should be malicious, such as stealing cookies from the target page, privacy information in local storage (such as account permission information and private key information), DOM tampering, request hijacking, clipboard content retrieval, etc. You can configure the relevant permissions in manifestion.json. If users do not pay attention to the permission application for extensions, it will be troublesome, but if an extension wants to do something bad and wants to directly engage in other extensions, such as well-known wallet extensions, it is still not easy... because the sandbox is isolated... for example, it is unlikely to directly steal the private key/mnemonic information stored in the wallet extension. If you are concerned about the permission risk of a certain extension, it is actually easy to determine this risk. After installing the extension, you can choose not to use it first. Look at the extension ID, search for the local path of the computer, find the manifestion.json file in the root directory of the extension, and directly throw the file content to AI for permission risk interpretation. If you have a mindset of isolation, you can consider enabling Chrome Profile separately for unfamiliar extensions, at least to control their wrongdoing, and the vast majority of extensions do not need to be constantly enabled.
+4
Mentioned
|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

Timeline

4月 14, 07:51【The gameplay is upgrading, combining multiple elements】
4月 14, 07:38【New gameplay created by meme+ai】
4月 13, 21:29【Community identifies threats to protect Ethereum】
4月 13, 20:20【Ethereum community concludes to extend L1】
4月 13, 20:00【DePIN mobile application based on avalanche inspires community】
4月 13, 03:00【Lead by example to improve community standards】
4月 11, 07:48【Morpho Labs confirms that the front-end security issue has been resolved】
4月 11, 06:00【MCP is a good subject matter】
4月 08, 07:00【AlphaHunter Community Metrics Optimized Sorting Algorithm】
4月 08, 00:00【The project launches NFT on BNB Chain through StoryChain】

HotFlash

|
APP
Windows
Mac
Share To

X

Telegram

Facebook

Reddit

CopyLink

APP
Windows
Mac

X

Telegram

Facebook

Reddit

CopyLink

Hot Reads