Collected research
The unexpected Google wide domain check bypass
A URL-parsing regex used across Google products ended the authority only at slash, question mark or hash, while browsers also end it at a backslash. A host written as attacker.tld then a backslash then something.corp.google.com passed an ends-with whitelist while the browser kept the attacker origin, so an embedded console iframe posted the victim's API key to the attacker.
Record
- Researcher
- David Schütz and @xdavidhu
- Published by
- bugs.xdavidhu.me
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of David Schütz and @xdavidhu, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .