Collected research
XSS in GMAIL Dynamic Email
XSS in GMAIL Dynamic Email (AMP for Email)
Gmail's AMP for Email sanitizer could be escaped from inside a style amp-custom block: the parser acted on an unterminated closing style tag and auto-generated closing tags, letting injected markup break into the document body. Only a meta refresh survived the tag filter, navigating the mail view to a data URL; Gmail's CSP blocked script execution. Google paid a 6,000 dollar bounty.
Record
- Document
- XSS in GMAIL Dynamic Email (AMP for Email)
- Researcher
- asdqw3
- Published by
- Medium
- Date
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of asdqw3, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .