Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Bypassing CSP with dangling iframes

Summary

A CSP bypass found when Chrome 97 broke a dangling-markup lab: setting a cross-domain iframe to about:blank hands ownership to the attacker, exposing window.name and running script despite CSP.
Published
Collected

original ↗

Related coverage

back