Collected research
Hijacking service workers via DOM Clobbering
Service workers configured from the page, by a query-string parameter or by the innerText of an element fetched with document.getElementById, can be made to pass an attacker host to importScripts(). Injecting an html or body tag carrying the same id clobbers that lookup, so injected markup alone yields persistent site takeover that also evades HTML filters and CSP.
Record
- Researcher
- Gareth Heyes
- Published by
- PortSwigger Research
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Gareth Heyes, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .