Making Myself at Chrome: Stealthy Local Backdoors for Signal, 1Password, Slack, and more

No ratings

Presented at DistrictCon Year 1 by

Electron applications use the Chromium engine’s V8 heap snapshot mechanism to improve app startup time. Unlike bundled code, snapshots are not signed, allowing attackers to plant stealthy backdoors in a valid code-signed application using a tailor-made malicious snapshot. Signal, 1Password, and Slack were previously all vulnerable to this attack, despite enabling Electron’s strictest integrity checking and code-signing features. Even more concerning, this vulnerability extends beyond Electron to potentially affect all Chromium-based applications including Chrome itself.