harden: escape every interpolation into popup innerHTML, and add default-src to both manifests (closes #307)
All checks were successful
check / check (push) Successful in 28s
e2e / e2e-chrome (push) Successful in 1m10s
e2e / e2e-firefox (push) Successful in 22s

A hostile ERC-20's symbol() reached an innerHTML string unescaped, and neither
manifest declared default-src, so an attacker deploying a token with 1,000+
holders and airdropping one unit could render a full-viewport cross-origin
iframe over the wallet's own UI, on screens where the user types their
password.

escapeHtml is now a pure string replace over & < > " ' — the old version
round-tripped through textContent, which escapes neither quote, while already
being used inside data-copy="...". All 19 files in src/popup/views/ were
audited: beyond the reported symbol site, the explorer-supplied directionLabel
in all three transaction lists, wallet.name, addr.ensName, the blockie data:
URIs and two ad-hoc quote-only escapes were also unescaped. Explorer URLs now
go through one helper that percent-encodes the path segment.

Both manifests add default-src 'self', frame-src 'none', form-action 'none' and
base-uri 'none'. Three loosenings are pinned in tests/manifest.test.js and
justified in README.md: style-src 'unsafe-inline' (39 static style attributes;
Firefox implements neither style-src-attr nor 'unsafe-hashes'), img-src data:
(blockies), connect-src https: http: (user-configurable RPC).

Note frame-src 'none' blocks a frame loading, not the element existing, so the
zero-iframe assertion is a claim about the escaping alone; the test asserts the
element count and the literal rendered text separately, taking the count before
any click an overlay could intercept.

Verified: make check 39 suites / 811 tests, test-e2e 55/55 including the
WebAssembly-under-CSP assertion, test-e2e-firefox 8/8, zero CSP violations
asserted rather than merely unobserved. Reverting only balanceLine's
interpolation reproduces the attack as 2 iframes on the address screen.
This commit was merged in pull request #327.
This commit is contained in:
2026-08-20 13:47:28 +02:00
parent 59f68b8859
commit c8c2af0c6b
24 changed files with 706 additions and 97 deletions

41
src/shared/html.js Normal file
View File

@@ -0,0 +1,41 @@
// HTML escaping for values interpolated into an innerHTML string.
//
// Every view in src/popup/views/ builds markup by string concatenation, so
// this is the only thing standing between a value the wallet did not author
// and the extension's own DOM. The values that reach it are attacker
// controlled by design: an ERC-20's symbol() and name() are whatever the
// contract chooses to return, an ENS name is whatever the resolver returns,
// and both arrive through the block explorer with no schema.
//
// It escapes both quote characters as well as the tag delimiters, because
// the popup interpolates into attribute values as well as into element
// text — copyableHtml() writes data-copy="..." and etherscanLinkHtml()
// writes href="...". A `<`/`>`-only escape leaves an unquoted-attribute
// break-out intact, and the round trip through a detached element's
// textContent that used to implement this was exactly that escape: the
// HTML serializer only escapes `&`, `<`, `>` and U+00A0 in a text node,
// since a text node has no idea it is about to be pasted inside quotes.
//
// Deliberately a pure string function with no DOM dependency: it is called
// on every rendered row, it is unit-testable without a document, and it
// cannot be affected by the state of a document that an attacker-supplied
// string has already been written into.
const HTML_ESCAPES = {
"&": "&amp;",
"<": "&lt;",
">": "&gt;",
'"': "&quot;",
"'": "&#39;",
};
// `&` is escaped first by virtue of being in the same pass: a sequential
// replace would re-escape the ampersands it had just introduced.
function escapeHtml(s) {
if (s === null || s === undefined) return "";
return String(s).replace(/[&<>"']/g, (c) => HTML_ESCAPES[c]);
}
module.exports = {
escapeHtml,
};

View File

@@ -0,0 +1,43 @@
// The length bound on a token symbol as displayed.
//
// A symbol is whatever an ERC-20's symbol() returns and the wallet fetches
// it from the block explorer, which imposes no length: src/shared/balances.js
// takes `item.token.symbol` as given. A kilobyte-long symbol is a real
// return value, and rendering it pushes every amount off the row, scrolls
// the balance list past the screen, and hides the figures the user is there
// to read.
//
// This is a layout bound, not a security control. Escaping is what makes a
// hostile symbol inert (see src/shared/html.js), and isSpoofedSymbol() is
// what catches one impersonating a known ticker; neither job belongs here
// and neither is done here. Truncating an unescaped symbol would still be
// an injection, just a shorter one.
//
// 12 characters, which is the bound lookupTokenInfo() in
// src/shared/balances.js already applies when it stores a symbol read
// straight off a contract; the explorer path was the one with no bound at
// all. The longest symbol across the 512 entries of the bundled list is 10
// (MSYRUPUSDP), so nothing the wallet ships as a real token is ever
// truncated. The ellipsis is what tells the user the name they are looking
// at is not the whole name — worth knowing before they send to it.
const MAX_SYMBOL_LENGTH = 12;
// The placeholder for a token whose symbol the explorer did not report.
// balances.js already substitutes this; repeated here so a symbol that
// arrives empty from anywhere else displays the same way rather than as a
// blank gap in the row.
const UNKNOWN_SYMBOL = "???";
function displaySymbol(symbol) {
const s = symbol === null || symbol === undefined ? "" : String(symbol);
if (s.length === 0) return UNKNOWN_SYMBOL;
if (s.length <= MAX_SYMBOL_LENGTH) return s;
return s.slice(0, MAX_SYMBOL_LENGTH - 1) + "…";
}
module.exports = {
displaySymbol,
MAX_SYMBOL_LENGTH,
UNKNOWN_SYMBOL,
};