Later archive addition
Steam, Fire and Paste: UXSS via DOM XSS and clickjacking
The write-up chains a DOM-based XSS and clickjacking weakness in the Steam Inventory Helper extension into universal cross-site scripting. A malicious page manipulates privileged extension UI and execution paths to run script in arbitrary origins available to the browser.
Record
- Researcher
- @IAmMandatory
- Published by
- The Hacker Blog
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @IAmMandatory, first published at the original source. Preserved copies are kept so the citation survives its host.