Hacking Browsers: The Easy Way | Hacker Summer 2026 Community Session 1

Hacking Browsers: The Easy Way | Hacker Summer 2026 Community Session 1

Source: YouTube · Altered Security · published Jul 27, 2026 · 51:01

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

BLUF: Security researcher Robert Hui reveals that browsers are vulnerable to simple, creative exploits rather than complex memory bugs, demonstrating attacks ranging from legacy feature abuse to AI prompt injection 2:15.

Key Takeaways:
Local File Inclusion via OBS: Exploiting a legacy http://absolute URI feature in OBS's CEF browser allows attackers to force the browser to treat a remote WebDAV domain as a local file source, bypassing Same-Origin Policy to read local files 10:07.
File Extension Bypass in Chrome: The File System Access API allows attackers to save a file with a safe extension (e.g., .jpg) after user permission, then rename it to an executable (e.g., .exe) before the user opens it, bypassing security warnings 31:21.
Stealing Private Repositories via "Enter Jacking": Attackers steal private GitHub repositories by tricking users into holding the Enter key, which auto-confirms the file save dialog for a zip download, while exploiting a race condition where the file handle remains valid after deletion 35:52.
Universal "Enter Jacking" on Linux: This technique extends to Linux distributions, allowing attackers to steal recently uploaded files from any website by forcing the browser to auto-select and confirm the previous file upload 41:06.
Firefox AI Prompt Injection: A simple prompt injection in Firefox’s sidebar AI agent allows attackers to extract saved memories (like passwords) by using non-English languages to bypass guardrails and forcing the agent to make external requests 42:41.

Closing Statement:
These examples illustrate that simple, creative attacks on browser features and legacy c

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Hello everyone. Can you guys hear and see me? Let me share my screen. There we go. Welcome. Welcome, everyone. I think I am
good to just go ahead and get started. Or does anyone from Altered Security. Want to jump in quickly? So welcome everyone to this session. So eugenics to altered security
for making this possible and having these sessions
throughout the summer. There's a lot of,
a lot of big events going on, but not everybody is able to go
to the big hacker summer camp events. So it's awesome to see that
these kinds of things do exist as well. That is great. So this is a part of hacker Summer. It's a month long event with a bunch of
talks about all different kinds of stuff. So really excited
that I'm able to do this. If there are any questions you can ask them on discord,
I am not yet…