Open Jack-Works opened 3 years ago
MetaMask's browser extension uses SES. See MetaMask/metamask-extension#9468 for links to relevant PRs.
I have updated use cases
eval()
is still supported in sandboxed pages. These pages have extremely limited access to extension APIs which minimizes the risk posed by eval. It's possible to use WebAssembly through the wasm-unsafe-eval
CSP directive. For details see this comment on issue 98.
Chrome bans
eval
totally in MV3Use cases
Use Secure ECMAScript to prevent supply chain attacks
eval
is required.Load WebAssembly modules