• midribbon_action@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    39
    ·
    13 hours ago

    The article says that is the intended use, I agree this is just bad implementation, but it’s bad because it not only allows control one way, from the app to the browser, it also allows it the other way: browser extensions with an ID that matches one of the allowed ones can access userspace, without asking. That is a huge attack surface that is installed without any consent.