Collected research
Cross-Site WebSocket Hijacking Exploitation in 2025
Cross-Site WebSocket Hijacking lets a malicious page open an authenticated WebSocket to a server that skips the handshake Origin check, then send and read messages as the victim. Re-tested against current browsers: Chrome's SameSite default forces the cookie to SameSite=None, Firefox Total Cookie Protection blocks it, and Private Network Access does not stop it on private addresses.
Record
- Researcher
- Laurence Tennant and @includesecurity
- Published by
- Include Security Research Blog
- Date
- Topic
- HTTP
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Laurence Tennant and @includesecurity, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .