Collected research
Security analysis of portal element
Security analysis of <portal> element
Security review of Chrome's new portal element, which embeds a page that behaves like a top-level frame. It accepted file, chrome and javascript URLs for cross-origin script execution, ignored X-Frame-Options, allowed keyboard-driven clickjacking, leaked cross-site state and open ports by counting onload events, received SameSite cookies, and permitted dangling-markup exfiltration.
Record
- Document
- Security analysis of <portal> element
- Researcher
- @SecurityMB
- Published by
- research.securitum.com
- Date
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of @SecurityMB, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .