DevTools leak information about CSP violations
2024-06-30 by Yannik Marchand
This post describes a minor vulnerability in Firefox, that Aidan Stephenson and I discovered while playing DiceCTF. In short, an attacker that had access to an HTML injection vulnerability could leak secrets from this page if the victim had the DevTools open, even with a strict content security in place … Read more...
Vulnerability