Preliminary research
The Last Writer Wins: A Chess.com Account Takeover via postMessage XSS
AI-collected research leads through 29 September 2026, including targeted additions between broader sweeps. Unranked, incomplete, not community-vetted, and subject to change.
A Chess.com postMessage handler accepted foreign-origin state. Its HTML wrapper removed diagram comments before DOMPurify, then restored them into attacker-placed placeholder tokens inside attributes, creating XSS. The account-takeover example depends on an authenticated SSO-created account that can set its first password without an old one.
Record
- Researcher
- XENOPS Research
- Published by
- XENOPS
- Date
- Topic
- XSS
In the archive
Related sources
- Code Vulnerabilities Put Proton Mails at Risk
- Earlier placeholder-collision fix (2020)
- Earlier remove-sanitize-restore example (June 2026)
Tags
This page is the archive's own catalogue record. The research is the work of XENOPS Research, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .