Skip to content

BenMullan/ece-talk

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

19 Commits
 
 
 
 
 
 
 
 

Repository files navigation

embedded Chromium everywhere!

...a security look at msedgewebview2 + CDP

Watch this talk on YouTube!


hello! Millions of desktop applications (eg: zoom, steam, & vscode) ship a full Chromium browser with a debug-socket backdoor baked in. I examine how CDP — the protocol that powers devtools — creates some minor weaknesses in Electron- and MsEdgeWebView2-based software. Live demo included!

useful bits...

proof-of-concept screenshots...








slides...













































































About

Resources from my talk, "embedded chromium everywhere! a security look at msedgewebview2 + CDP"

Resources

Stars

Watchers

Forks

Contributors