Root cause
The messaging boundary treated caller-influenced context as authority for extension-worker operations. Browser framing permission did not independently establish that embedded content should control the worker.
Demonstrated impact
The researcher demonstrated script execution in a worker, without direct DOM access. Same-origin requests were described as a possible consequence; broader account takeover was not established. The reproduced award notice limits severity because prior access to an affected resource was required.
Lessons for review
- Bind messaging trust to a verified origin and context.
- Review nested rendering and worker privileges together.
- Validate message authority independently of framing permission and keep untrusted rendered content separate from privileged extension operations.
Award and evidence
The image states a $22,500 award. USD follows Google web VRP denomination documented by google-usd-context; no currency conversion. Bonus mentioned but not separately itemized. Settlement date unknown.
Fresh-read the article; retained previously inspected award-image and currency evidence without advancing their retrieval times. No testing performed.
- Award evidence is not an independently audited cash receipt.
- The image is researcher-published, not independently retrieved vendor correspondence.
- Exact original-report, award, payment, fix and first-disclosure dates are unavailable. The linked Bug Hunters report returned no readable text.
- Article credits Matan Berson for the underlying discovery and Sreeram and Sivanesh for supporting research; recipient split is not stated.
- Parts of the explanation use a local Code OSS reconstruction; the author acknowledges incomplete historical IDX notes. It is not a verified account of current product behavior.
Recorded timeline
- Published
- 2025-07-02explicit · Date displayed by the researcher article.
- Reported
- 2024inferred · Article says the report was submitted last year; year inferred from its 2025 publication header.
Sources and provenance
- XSS in Google IDX Workstation sudi (Sudistark) · reviewed 2026-10-03
- Researcher-published Google award email for IDX report sudi (Sudistark), reproducing a Google award notice · reviewed 2026-10-02
- Google and Alphabet VRP reward-denomination announcement, July 11, 2024 Sam Erb and Krzysztof Kotowicz / Google · reviewed 2026-10-02
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.