Web Hack List

Collected research

Cross-Site WebSocket Hijacking Exploitation in 2025

Cross-Site WebSocket Hijacking lets a malicious page open an authenticated WebSocket to a server that skips the handshake Origin check, then send and read messages as the victim. Re-tested against current browsers: Chrome's SameSite default forces the cookie to SameSite=None, Firefox Total Cookie Protection blocks it, and Private Network Access does not stop it on private addresses.

Record

Researcher
Laurence Tennant and @includesecurity
Published by
Include Security Research Blog
Date
Topic
HTTP

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Laurence Tennant and @includesecurity, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .