Web Hack List

Collected research

Security analysis of portal element

Security analysis of <portal> element

Security review of Chrome's new portal element, which embeds a page that behaves like a top-level frame. It accepted file, chrome and javascript URLs for cross-origin script execution, ignored X-Frame-Options, allowed keyboard-driven clickjacking, leaked cross-site state and open ports by counting onload events, received SameSite cookies, and permitted dangling-markup exfiltration.

Record

Document
Security analysis of <portal> element
Researcher
@SecurityMB
Published by
research.securitum.com
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of @SecurityMB, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .