iframe-embedding

1 article
sort: new top best
clear filter
0 6/10

Google Docs lacks X-Frame-Options headers, allowing attackers to embed the voice typing feature in iframes on arbitrary sites and trick users into granting microphone access to record private conversations. The vulnerability was awarded a $2,337 bounty by Google.

Google Docs Raushan Raj Google VRP
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 11 hours ago · details