Collected research
Modern Alchemy: Turning XSS into RCE
Electron's nodeIntegration flag should keep untrusted pages away from Node, but window.open returns a proxy object that bypasses the same-origin policy, and evaluating script inside the privileged chrome-devtools window restores require. Any cross-site scripting in an Electron app therefore becomes code execution on the desktop.
Record
- Researcher
- Luca Carettoni
- Published by
- blog.doyensec.com
- Topic
- XSS
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Luca Carettoni, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .