Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Escaping '<' and '>' in attributes – how it helps protect against mutation XSS

Summary

Google's Bug Hunters explain why the HTML standard now escapes angle brackets in attribute values and how this change helps prevent mutation XSS (mXSS) attacks.
Published
Collected

original ↗

Related coverage

back