Abusing Chrome's XSS auditor to steal tokens
portswigger.net | research | #browser-security | #chrome | #side-channel | #token-theft | #xss-auditor
Summary
Gareth Heyes abuses Chrome's XSS Auditor block mode as a side-channel oracle, brute-forcing values such as user IDs embedded in inline scripts and stealing tokens. Includes working PoC code.
- Published
- Collected
Skip to content