Web Hack List

Collected research

Permission Hijacking at Scale

Permissions delegated to an iframe cannot be revoked by the host page, prompts name the top-level origin rather than the frame, and delegated grants never re-prompt. Compromising one widely embedded support-chat vendor, through a markdown formaction XSS and an unsanitised widget parameter, hands an attacker camera, microphone and screen capture across every embedding site.

Record

Researcher
Alberto Fernandez-de-Retana
Published by
bubu
Date
Topic
Identity

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Alberto Fernandez-de-Retana, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .