Replies: 3 comments
-
A possible attack vector, courtesy of @ MaximusHaximus: |
Beta Was this translation helpful? Give feedback.
-
Per OWASP's Third Party Javascript Management cheatsheet:
I could not find a clear answer on what a "virtual iframe" is. It might be an iframe that is visually hidden similar to the solution Stripe uses
|
Beta Was this translation helpful? Give feedback.
-
We need to check security docs from the iframes with the sandbox attribute. https://developer.mozilla.org/en-US/docs/Web/HTML/Element/iframe#attr-sandbox and see if there are still issues. And then consider if VM allows similar options already (like spamming fetch requests). |
Beta Was this translation helpful? Give feedback.
-
With discussions around leveraging cross-domain iframes for security purposes gaining steam, let's collect information on whether those claims of security are reliable.
Please post any concerns or supporting docs/articles here
Beta Was this translation helpful? Give feedback.
All reactions