Browser Extension Security: Content Scripts, DOM Exfiltration and the Manifest V3 Reality
Browser extensions occupy a uniquely dangerous position in the security landscape. They are installed by users who trust them, they run inside the browser with elevated privileges, and they can touch every page you visit. More importantly, the security research community has largely ignored them in favour of server-side bugs,