Bypassing CSP with dangling iframes
portswigger.net | research | #web-security | #chrome | #iframes | #csp-bypass | #dangling-markup | #window-name
Summary
A CSP bypass found when Chrome 97 broke a dangling-markup lab: setting a cross-domain iframe to about:blank hands ownership to the attacker, exposing window.name and running script despite CSP.
- Published
- Collected
Skip to content