chrome-xss-auditor

2 articles
sort: new top best
clear filter
0 8/10

A detailed technical writeup on chaining eight XSS vulnerabilities at Airbnb by sequentially bypassing JSON encoding, XSS filters, WAF protection using null-byte injection, CSP rules, and Chrome's XSS auditor through the listing_frame embeddable endpoint. The exploitation leverages semicolon injection, null-byte WAF evasion, JSON encoder quirks, and CSP weaknesses.

Airbnb Ben Sadeghipour Brett Buerhaus HackerOne Chrome XSS Auditor
buer.haus · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details
0 7/10

XSS vulnerability in Facebook Studio discovered via incorrect Content-Type header (text/html instead of application/json) that allowed malicious JavaScript to bypass client-side escaping and XSS filters by exploiting content-type sniffing behavior. The vulnerability was fixed by correcting the Content-Type header to application/json.

Facebook Studio Facebook Chrome XSS Auditor IE XSS Filter Jack
whitton.io · devanshbatham/Awesome-Bugbounty-Writeups · 22 hours ago · details