Web Hack List

Collected research

XSS in Skype for iOS

XSS in Skype for iOS — Superevr

Skype 3.0.1 and earlier for iPhone renders chat in a local HTML file without encoding the sender's Full Name, so a crafted name runs JavaScript when the victim opens the message. Worse, the embedded WebKit view runs under the file:// scheme rather than about:blank, giving script read access to the app sandbox. The author demonstrates stealing the device AddressBook.

Record

Document
XSS in Skype for iOS — Superevr
Researcher
superevr
Published by
Superevr
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of superevr, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .