JSON hijacking for the modern web
portswigger.net | research | #web-security | #proxy | #json-hijacking | #edge | #cross-origin | #utf-16be
Summary
Gareth Heyes revives cross-domain JSON hijacking with JS proxies that capture undefined variables, plus an Edge bypass via Object.setPrototypeOf. A UTF-16BE charset trick makes JSON arrays stealable.
- Published
- Collected
Skip to content