Post #2822720
2025-03-13 12:40 UTC
@CuillereNessie@mastodon.social @yatil@yatil.social the problem is that this permission can be gamed (eg. https://www.malwarebytes.com/blog/news/2025/03/fake-captcha-websites-hijack-your-clipboard-to-install-information-stealers) and the normative requirements on user agents https://www.w3.org/TR/clipboard-apis/#privacy-async are not strong enough to mitigate these attacks.
Replies (2)
-
@CuillereNessie@mastodon.social 2025-03-13 12:47
@torgo@mastodon.social @yatil@yatil.social So if understand correctly edge does not provide the necessary protection from these kind of attack with the setting turned on. Is that right?
-
@Exagone313@share.elouworld.org 2025-03-14 08:22
@torgo@mastodon.social The article you linked is only describing a copy command, which is not something new and it is not related to the permission to see the content of the clipboard which landed last year. @CuillereNessie@mastodon.social @yatil@yatil.social