Comment #2 on issue 19403 by [email protected]: Need tests for an extension update being improperly signed http://code.google.com/p/chromium/issues/detail?id=19403
A somewhat related test we should also add is for the case of an update manifest mentioning updated extensions we didn't expect (eg extensions A and B, with different update_url's, are both installed, and the manifest for A includes a download link for a new version of B). Assuming we're doing the public key check right, I think the risk in this case is a denial-of-service type attack, by listing a large number of unexpected/bogus extensions in a manifest. -- You received this message because you are listed in the owner or CC fields of this issue, or because you starred this issue. You may adjust your issue notification preferences at: http://code.google.com/hosting/settings --~--~---------~--~----~------------~-------~--~----~ Automated mail from issue updates at http://crbug.com/ Subscription options: http://groups.google.com/group/chromium-bugs -~----------~----~----~----~------~----~------~--~---
