Nov 04

same origin policy bypass

Good cookies, bad cookies Let's take a look at an example. localStorage, indexedDB, BroadcastChannel, SharedWorker). UPchieve: Cross-origin resource sharing misconfig | steal user That means that SOP doesnt block