3 ms·
One is that if you open a window, you can change the URL that's loaded later. In the example that Google's page links to they change it to a data: URI - which
by parenthephobia 9y ago
One is that if you open a window, you can change the URL that's loaded later.
In the example that Google's page links to they change it to a data: URI - which no longer works in Chrome - but they could just as easily change it from http://good.com/ http://good.com/ to http://evil.com/ http://evil.com/ - which would still work in Chrome - and hope you don't notice.
- Ajedi32 9y agoBut how can they do that without access to `window.opener`?
- parenthephobia 9y agoIn the example, a nefarious page opens a new window and then uses its connection to that opened window - the window object is returned from "window.open()" - to manipulate it. No window.opener required, and the two windows don't even need to be in the same website for this to work. Google's page isn't just about abusing "window.opener", it's generally about abusing JavaScript-accessible connections between windows/tabs. Additionally, the site it's in isn't about browser bugs, but bugs in Google's websites. Google knows these issues are fixable, but they consider them to be flaws in browsers rather than in their websites. That's why Google says it's still easy to exploit the other vectors for the attack. A website can protect itself by clearing "window.opener", but similar attacks are possible that a website can't prevent. e.g. A window can't prevent the window that opened it from later forcing it to navigate to a different URL.