Collected research
On the Content Security Policy Violations due to the Same-Origin Policy
Examines how scripts in same-origin parent pages and iframes can bypass each other’s differing CSP restrictions. A crawl of over one million pages identifies potentially vulnerable page–iframe pairs, including cases requiring origin relaxation. The paper also finds browser differences in CSP inheritance for sandboxed srcdoc iframes and discusses origin-wide policy enforcement.
Record
- Researcher
- Dolière Francis Somé, Nataliia Bielova and Tamara Rezk
- Published by
- arxiv.org
- Format
- Whitepaper
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Dolière Francis Somé, Nataliia Bielova and Tamara Rezk, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .