Back to directory
WRITEUP #989

Linux local electron application script-src: self bypass

XSSElectronCSP bypassRCE
by@kevin_mizu(Mizu)
Program
-
Published
Jul 4, 2023
Added to HackDex
Jul 12, 2023
Read Full Writeuphttps://mizu.re/post/linux-local-electron-application-script-src-self-bypass#final_bypass
RELATED WRITEUPS
Evernote RCE: From PDF.js font-injection to All-platform Electron exposed ipcRenderer with listened BrokerBridge Remote-Code Execution
RCEXSS
Bypassing CSP via URL Parser Confusions : XSS on Netlify’s Image CDN
XSSCSP bypass
From MLOps to MLOops: Exposing the Attack Surface of Machine Learning Platforms
AI / LLMAI
Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!
RCEConfusion attack
Studying 0days: How we hacked Anki, the world's most popular flashcard app
RCEComponents with known vulnerabilities

Built with ❤️ by Shubham Rawat