Skip to content

Security: testy-cool/crxctl

SECURITY.md

Security policy

Reporting a vulnerability

Please use GitHub's private vulnerability reporting for this repository. Do not open a public issue for a vulnerability that could let another local process control Chrome extensions, bypass the bridge's operation allowlist, or access data outside the documented cache.

Include the affected commit, operating system, Chrome or Chromium version, Vicinae version, reproduction steps, and the security boundary you believe was crossed. Do not include real browser-profile data, credentials, or unrelated extension data.

Security model

The project deliberately keeps the control surface narrow:

  • The Chrome bridge has management, nativeMessaging, and offscreen, but no webpage host permissions.
  • The native host accepts only list, setEnabled, reload, and icon requests with validated fields.
  • The Unix socket, icon cache, and activity log are created for the current user only.
  • The bridge refuses operations that would disable or reload itself.
  • There is no uninstall, arbitrary command, shell, arbitrary file, or network operation.
  • Icons are restricted to known sizes and cached locally with user-only directory permissions.

The CLI accepts an exact extension ID or an exact, unambiguous display name. Names are treated as untrusted text and are never interpreted as shell input. The user who owns the desktop session and socket is trusted. Other extensions listed by Chrome are treated as untrusted data: names and versions are displayed as text and never executed.

There aren't any published security advisories