Collected research
Permission Hijacking at Scale
Permissions delegated to an iframe cannot be revoked by the host page, prompts name the top-level origin rather than the frame, and delegated grants never re-prompt. Compromising one widely embedded support-chat vendor, through a markdown formaction XSS and an unsanitised widget parameter, hands an attacker camera, microphone and screen capture across every embedding site.
Record
- Researcher
- Alberto Fernandez-de-Retana
- Published by
- bubu
- Date
- Topic
- Identity
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Alberto Fernandez-de-Retana, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .