Web Hack List

Collected research

Same Origin Policy: Evaluation in Modern Browsers

Same-Origin Policy: Evaluation in Modern Browsers

An empirical evaluation of the same-origin rules governing access between a host document and an embedded one. Running 544 test cases on ten browsers shows access rights depend not only on origin but on the type of the embedding element and on sandbox and CORS attributes, and that roughly 23 percent of cases behave differently between browsers, with the Microsoft findings acknowledged.

Record

Document
Same-Origin Policy: Evaluation in Modern Browsers
Researcher
Jörg Schwenk, Marcus Niemietz and Christian Mainka
Published by
usenix.org
Topic
Browser

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Jörg Schwenk, Marcus Niemietz and Christian Mainka, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .