3 ms·
I'm sorry if I misunderstand, but what you linked is related to allowing user created css to be displayed on a service? I don't think it's exactly relevant here
by httpsterio 6y ago
I'm sorry if I misunderstand, but what you linked is related to allowing user created css to be displayed on a service? I don't think it's exactly relevant here. If you're just adding custom css on the page that'd displayed for you, there's no attack vector, but those links in the SO is about injected CSS where the attacker loads custom CSS for other visitors.
It's almost trivial to set up a keylogger with css that fires requests on keyboard input. Luckily there's CSP.