Preliminary research
Two Bypasses for Chrome's Sanitizer API
Two Bypasses for Chrome’s Sanitizer API
AI-collected research leads through 22 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
Two ways past Chrome's built-in Sanitizer API, including a javascript: URL that survives sanitisation because a U+2028 line separator splits the scheme token the parser checks against the one it later resolves.
Record
- Document
- Two Bypasses for Chrome’s Sanitizer API
- Researcher
- Adam Kues and @searchlightsec
- Published by
- Searchlight Cyber
- Date
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Adam Kues and @searchlightsec, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .