Collected research
JSON hijacking for the modern web
Combines JavaScript Proxy traps with UTF-16BE script decoding to turn cross-origin JSON into undeclared variable names and recover their contents. Browser-specific prototype-chain tricks expose data in Edge, Chrome and Safari. The article also develops an injection-assisted variant without proxies and a CSP bypass, and explains why explicit response charsets prevent the charset attacks.
Record
- Researcher
- Gareth Heyes
- Published by
- PortSwigger
- Date
- Topic
- Other
In the archive
Related sources
- JSON Hijacking for the Modern Web Whitepaper
- Edge undefined-variable read
- Edge undefined-variable read: method 2
- Edge JSON feed disclosure
- Chrome JSON feed disclosure
- Safari JSON feed disclosure
- JSON feed disclosure without proxies
- Takeshi Terada’s XSSI paper Whitepaper
- Multiple undefined variables in Edge
- CSP bypass using UTF-16BE PoC
Tags
This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .