Collected research
The Remote on the Local: Exacerbating Web Attacks Via Service Workers Caches
Existing same-origin malicious JavaScript can rewrite service-worker caches to remove CSP and other security headers, reorder cached scripts, and persist attacks after server fixes. Cached authenticated responses can also remain readable after logout. The paper proposes restricting page access to worker caches.
Record
- Researcher
- Dolière Francis Somé, Stefano Calzavara, Marco Squarcina and Matteo Maffei
- Published by
- secweb.work
- Format
- Whitepaper
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Dolière Francis Somé, Stefano Calzavara, Marco Squarcina and Matteo Maffei, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .