4 ms·
This is not entirely correct. An SVG file embedded in an <iframe> or <object> is a document itself, and if cross-origin, can not access the outer document. Howe
by felixfbecker 6y ago
This is not entirely correct. An SVG file embedded in an <iframe> or <object> is a document itself, and if cross-origin, can not access the outer document. However, if not in a sandboxed iframe, it can still do things like trigger alert prompts or navigation.
- eyelidlessness 6y agoSorry, this is right. I should have said it’s just as capable or limited in SVG as a bare script tag in the same place.