Collected research
CVE-2022-4908: SOP bypass in Chrome using Navigation API
Chrome's Navigation API copied navigation.entries() from the previous document when a window or frame was navigated to about:blank, so a same-site but cross-origin page could read the target window's full history URLs (CVE-2022-4908). Combined with broken OAuth flows this exfiltrates codes and tokens, turning a subdomain XSS or takeover into account takeover.
Record
- Researcher
- Johan Carlsson and @joaxcar
- Published by
- Johan Carlsson
- Date
- Format
- Advisory
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Johan Carlsson and @joaxcar, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .