Collected research
Safari: a tale of betrayal and revenge
Explains a Safari same-origin bypass caused by disagreement between WebKit’s KURL parser and CFNetwork. Hostless-looking HTTP URLs receive authenticated content from distinct servers while origin checks treat both as having an empty host. A data-URL transition supplies the parsing context needed to trigger the discrepancy from a webpage; Safari 4.1 and 5.0 fixed the flaw.
Record
- Researcher
- Michał Zalewski
- Published by
- lcamtuf.blogspot.com
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Michał Zalewski, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .