Web Hack List

Collected research

FuzzOrigin: Detecting UXSS vulnerabilities in Browsers through Origin Fuzzing

FuzzOrigin fuzzes browsers for universal cross-site scripting, generating HTML and JavaScript that drives frequent navigations and chained event handlers, then detecting when a script executes under an origin it should not have. It found nineteen UXSS bugs in Chrome and Edge, letting an attacker page run script in every other site the victim's browser loads.

Record

Researcher
Sunwoo Kim, Young Min Kim, Jaewon Hur, Suhwan Song, Gwangmu Lee and Byoungyoung Lee
Published by
usenix.org
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Sunwoo Kim, Young Min Kim, Jaewon Hur, Suhwan Song, Gwangmu Lee and Byoungyoung Lee, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .