XS-Leak: Leaking IDs using focus
portswigger.net | research | #browser-security | #portswigger | #side-channel | #focus | #xs-leak | #cross-origin | #iframe
Summary
Gareth Heyes leaks element IDs cross-domain by abusing URL fragment scrolling and focus events in an iframe, brute-forcing IDs with just a single page load.
- Published
- Collected
Skip to content