sandboxed-iframe

1 article
sort: new top best
clear filter
0 6/10

A clickjacking vulnerability in Telegram's web client allowed attackers to bypass frame-busting protections using sandboxed iframes and block CSS stylesheets via MITM attacks, enabling account compromise and unauthorized message sending. The vulnerability was fixed by Telegram implementing proper X-Frame-Options headers.

Telegram Mohamed A. Baset Seekurity Pavel Durov
seekurity.com · devanshbatham/Awesome-Bugbounty-Writeups · 11 hours ago · details