Collected research
XSS in Skype for iOS
XSS in Skype for iOS — Superevr
Skype 3.0.1 and earlier for iPhone renders chat in a local HTML file without encoding the sender's Full Name, so a crafted name runs JavaScript when the victim opens the message. Worse, the embedded WebKit view runs under the file:// scheme rather than about:blank, giving script read access to the app sandbox. The author demonstrates stealing the device AddressBook.
Record
- Document
- XSS in Skype for iOS — Superevr
- Researcher
- superevr
- Published by
- Superevr
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of superevr, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .