Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Do not do same-URL replace navigations when initiated cross-origin #9157

Merged
merged 1 commit into from
May 8, 2023

Conversation

domenic
Copy link
Member

@domenic domenic commented Apr 13, 2023

This allows attackers to do a boolean probe on the URL of a cross-origin iframe, by attempting to navigate it to a given URL, and if history.length does not increase, they know that the iframe is currently pointed to that URL. Closes #2018, at least the actionable part where you can get more information than just what is retrieved using the load event.

/cc @petervanderbeken since I was reminded of this when working on #9135.

(See WHATWG Working Mode: Changes for more details.)


/browsing-the-web.html ( diff )

This allows attackers to do a boolean probe on the URL of a cross-origin iframe, by attempting to navigate it to a given URL, and if history.length does not increase, they know that the iframe is currently pointed to that URL.
@domenic domenic merged commit dc564b9 into main May 8, 2023
@domenic domenic deleted the no-crossorigin-same-url-replace branch May 8, 2023 22:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

Successfully merging this pull request may close these issues.

Should History.length really be cross-domain [XSHM breach]?
2 participants