components that execute scripts / filters on webpages should have integrity protection #42274
Labels
OS/Desktop
priority/P2
A bad problem. We might uplift this to the next planned release.
sec-high
security
Brave's components should have integrity protection similar to extensions from the Chrome Web Store: https://github.com/brave/reviews/issues/1783#issuecomment-2469787880. If developers need to bypass this while testing out component changes, they can launch Brave with a special command line flag similar to the
--load-extension
flag in Chrome.The custom filters/scriptlets feature should be gated behind a secure pref, similar to the "developer mode" extensions toggle: https://github.com/brave/reviews/issues/1783#issuecomment-2458050497.
The text was updated successfully, but these errors were encountered: