Collected research
Zoom Session Takeover - Cookie Tossing Payloads, OAuth Dirty Dancing, Browser Permissions Hijacking, and WAF abuse
An XSS in a nonce cookie reflects into every CSP nonce on the domain; an XSS on a neglected subdomain tosses that cookie across the domain, giving persistent XSS nearly everywhere. The chain steals a Google authorization code by OAuth dirty dancing, reuses granted camera and microphone permissions, and tosses a script-tagged cookie so the WAF locks the victim out.
Record
- Researcher
- Sudi, BrunoZero and H4R3L
- Published by
- Harel Security Research
- Date
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Sudi, BrunoZero and H4R3L, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .