MicrosoftEdge / MicrosoftEdge/MSEdgeExplainers

[Web Install] Cross-origin installation phishing risk

Open
#774 2 comments 0 reactions 1 assignee View on GitHub

@diekus is already working on this.

Since Mar 13, 2024.

Web Install API
Dominant language
HTML
Stars
1.4k
Forks
286
Avg merge
3d 1h
Merged PRs (30d)
8

Description

(Issue raised by Nick Doty during W3C Breakout)

What is preventing an unvetted web app store from listing a malicious app for cross-origin installation that assumes the identity of a well-known app (gmail_s_.com)? What can the API do to mitigate opening up the surface for phishing attacks and preserve the security model of the web?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.