vulns.co
/
GKData.io MCP

BRClient and browser security · 2 min read

Google IDX worker messaging crossed browser trust boundaries

A browser-IDE trust-boundary report received a USD 22,500 award.

Read the primary source BRClient and browser securityReviewed 2026-10-03

Root cause

The messaging boundary treated caller-influenced context as authority for extension-worker operations. Browser framing permission did not independently establish that embedded content should control the worker.

Demonstrated impact

The researcher demonstrated script execution in a worker, without direct DOM access. Same-origin requests were described as a possible consequence; broader account takeover was not established. The reproduced award notice limits severity because prior access to an affected resource was required.

Lessons for review

  • Bind messaging trust to a verified origin and context.
  • Review nested rendering and worker privileges together.
  • Validate message authority independently of framing permission and keep untrusted rendered content separate from privileged extension operations.

Award and evidence

USD 22,500Bug Bounty · Researcher Reported With Vendor Quote

The image states a $22,500 award. USD follows Google web VRP denomination documented by google-usd-context; no currency conversion. Bonus mentioned but not separately itemized. Settlement date unknown.

Fresh-read the article; retained previously inspected award-image and currency evidence without advancing their retrieval times. No testing performed.

  • Award evidence is not an independently audited cash receipt.
  • The image is researcher-published, not independently retrieved vendor correspondence.
  • Exact original-report, award, payment, fix and first-disclosure dates are unavailable. The linked Bug Hunters report returned no readable text.
  • Article credits Matan Berson for the underlying discovery and Sreeram and Sivanesh for supporting research; recipient split is not stated.
  • Parts of the explanation use a local Code OSS reconstruction; the author acknowledges incomplete historical IDX notes. It is not a verified account of current product behavior.

Recorded timeline

Published
2025-07-02explicit · Date displayed by the researcher article.
Reported
2024inferred · Article says the report was submitted last year; year inferred from its 2025 publication header.

Sources and provenance

  1. XSS in Google IDX Workstation sudi (Sudistark) · reviewed 2026-10-03
  2. Researcher-published Google award email for IDX report sudi (Sudistark), reproducing a Google award notice · reviewed 2026-10-02
  3. Google and Alphabet VRP reward-denomination announcement, July 11, 2024 Sam Erb and Krzysztof Kotowicz / Google · reviewed 2026-10-02

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software