Web Hack List

Collected research

CVE-2022-4908: SOP bypass in Chrome using Navigation API

Chrome's Navigation API copied navigation.entries() from the previous document when a window or frame was navigated to about:blank, so a same-site but cross-origin page could read the target window's full history URLs (CVE-2022-4908). Combined with broken OAuth flows this exfiltrates codes and tokens, turning a subdomain XSS or takeover into account takeover.

Record

Researcher
Johan Carlsson and @joaxcar
Published by
Johan Carlsson
Date
Format
Advisory
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Johan Carlsson and @joaxcar, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .