Breaking Chrome’s AppBound Cookie Encryption Key
Chrome的AppBound Cookie加密机制存在漏洞,其依赖的密钥导出过程熵值有限且输入可预测。攻击者可利用已知参数生成可能密钥并暴力破解,无需权限或代码执行即可解密所有受保护Cookie,破坏其在企业环境中的隔离功能。 2025-6-30 17:8:58 Author: www.reddit.com(查看原文) 阅读量:11 收藏

The research shows that Chrome’s AppBound cookie encryption relies on a key derivation process with limited entropy and predictable inputs. By systematically generating possible keys based on known parameters, an attacker can brute-force the correct encryption key without any elevated privileges or code execution. Once recovered, this key can decrypt any AppBound-protected cookies, completely undermining the isolation AppBound was intended to provide in enterprise environments.


文章来源: https://www.reddit.com/r/ReverseEngineering/comments/1lod46a/breaking_chromes_appbound_cookie_encryption_key/
如有侵权请联系:admin#unsafe.sh