Browser extension question: What's the worst thing one can do with HTML injection into a browser action pop-up? Default CSP won't allow running JavaScript, redirects or links to web pages don't work. Spoofing potential seems limited. Anything I am missing? #infosec #xss #webext