Web Hack List

Collected research

On the Content Security Policy Violations due to the Same-Origin Policy

Examines how scripts in same-origin parent pages and iframes can bypass each other’s differing CSP restrictions. A crawl of over one million pages identifies potentially vulnerable page–iframe pairs, including cases requiring origin relaxation. The paper also finds browser differences in CSP inheritance for sandboxed srcdoc iframes and discusses origin-wide policy enforcement.

Record

Researcher
Dolière Francis Somé, Nataliia Bielova and Tamara Rezk
Published by
arxiv.org
Format
Whitepaper
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Dolière Francis Somé, Nataliia Bielova and Tamara Rezk, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .