Collected research
Nonce CSP bypass using Disk Cache
Turns an HTML injection into XSS under a nonce-based policy. CSS injection leaks the nonce from the meta policy tag, then forcing a fall back to disk cache replays the page with its old nonce while login CSRF and cache partitioning refresh only the separately fetched injected payload, so the attacker's script carries a nonce the page still trusts.
Record
- Researcher
- Jorian Woltjer
- Published by
- jorianwoltjer.com
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Jorian Woltjer, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .