Web Hack List

Collected research

XSS in GMAIL Dynamic Email

XSS in GMAIL Dynamic Email (AMP for Email)

Gmail's AMP for Email sanitizer could be escaped from inside a style amp-custom block: the parser acted on an unterminated closing style tag and auto-generated closing tags, letting injected markup break into the document body. Only a meta refresh survived the tag filter, navigating the mail view to a data URL; Gmail's CSP blocked script execution. Google paid a 6,000 dollar bounty.

Record

Document
XSS in GMAIL Dynamic Email (AMP for Email)
Researcher
asdqw3
Published by
Medium
Date
Topic
XSS

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of asdqw3, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .