Skip to content

Conversation

@RinZ27
Copy link
Contributor

@RinZ27 RinZ27 commented Jan 8, 2026

The ai.gemini-on-device-alt-texter sample currently requests <all_urls> host permissions.

Following the Principle of Least Privilege, I've replaced this with activeTab. This change provides necessary access to the current page only upon user interaction (via context menu), significantly reducing the extension's attack surface while maintaining full functionality.

@oliverdunk oliverdunk merged commit ddf0e9a into GoogleChrome:main Jan 8, 2026
2 checks passed
@RinZ27 RinZ27 deleted the security/harden-alt-texter-permissions branch January 9, 2026 12:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants