writeups.xyz writeups.xyz / PostMessage

Title Vulnerabilities Programs Authors
Security and Privacy of Social Logins (II): PostMessage Security in Single Sign-On
Bad regex used in Facebook Javascript SDK leads to account takeovers in websites that included it
[Google VRP] Hijacking Google Docs Screenshots
Facebook DOM Based XSS using postMessage
Hunting postMessage Vulnerabilities
Account takeover via postMessage
Exploiting post message to steal and replace user’s cookies
Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token