Collected research
All Your Screens Are Belong to Us: Attacks Exploiting the HTML5 Screen Sharing API
The HTML5 screen sharing extension to getUserMedia creates a cross-origin feedback loop: a site the user shares their screen with sees everything rendered, whatever its origin. An attacker opens authenticated cross-origin pages in the victim's browser and reads CSRF tokens, browsing history and private data, hiding the theft within the limits of human vision.
Record
- Researcher
- Yuan Tian, Ying-Chuan Liu, Amar Bhosale, Lin-Shung Huang, Patrick Tague and Collin Jackson
- Published by
- ieee-security.org
- Format
- Whitepaper
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Yuan Tian, Ying-Chuan Liu, Amar Bhosale, Lin-Shung Huang, Patrick Tague and Collin Jackson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .