Web Hack List

Collected research

Nonce CSP bypass using Disk Cache

Turns an HTML injection into XSS under a nonce-based policy. CSS injection leaks the nonce from the meta policy tag, then forcing a fall back to disk cache replays the page with its old nonce while login CSRF and cache partitioning refresh only the separately fetched injected payload, so the attacker's script carries a nonce the page still trusts.

Record

Researcher
Jorian Woltjer
Published by
jorianwoltjer.com
Topic
XSS

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Jorian Woltjer, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .