Collected research
Logically Bypassing Browser Security Boundaries
Origin checks fall when what a resource is changes after it is checked: a CSP-sandboxed frame fools the password manager, HTTP redirects and service workers swap sub-resources past the check, and HLS playlists leak cross-origin audio and video. A blob URL minted in a compromised renderer also escapes Chrome Site Isolation and reaches another site's cookies.
Record
- Researcher
- Jun Kokatsu
- Published by
- Speaker Deck
- Date
- Format
- Slides
- Topic
- Browser
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Jun Kokatsu, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .