Web Hack List

Collected research

Stealing local files using Safari Web Share API

Shows Safari accepting a local file URL supplied to the Web Share API and attaching the dereferenced file in the native share flow. A malicious page can obscure the attachment, turning the browser and share sheet into a user-mediated local-file disclosure path.

Record

Published by
REDTEAM.PL

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of REDTEAM.PL, first published at the original source. Preserved copies are kept so the citation survives its host.