Universal XSS

R3zk0n ยท October 2, 2025

Contents

    Basics

    • https://www.acunetix.com/blog/articles/universal-cross-site-scripting-uxss/

    2022 Safari UXSS

    • https://www.ryanpickren.com/safari-uxss
    • https://www.theregister.com/2022/01/26/apple_filesharing_exploit/

    2021 Microsoft Edge UXSS in Translator

    • https://cybersophia.net/news/universal-xss-vulnerability-in-microsoft-edge-cve-2021-34506/
    • https://blog.cyberxplore.com/how-we-are-able-to-hack-any-company-by-sending-message-20000-bounty-cve-2021-34506/
    • https://latesthackingnews.com/2021/06/30/universal-xss-vulnerability-in-microsoft-edge/

    2021 Google Chrome Dangerous XSS in New Tab

    • https://portswigger.net/daily-swig/dangerous-xss-bug-in-google-chromes-new-tab-page-bypassed-security-features

    2021 Duckduckgo UXSS in multiple browsers

    • https://cisomag.eccouncil.org/duckduckgo-quacks-again-about-uxss-vulnerability-in-multiple-browsers/

    2020 Evernote UXSS in Android Intent

    • https://blog.oversecured.com/Evernote-Universal-XSS-theft-of-all-cookies-from-all-sites-and-more/

    2020 Android WebView UXSS

    • https://alesandroortiz.com/articles/uxss-android-webview-cve-2020-6506/

    2018 Evernote UXSS in Webclipper

    • https://blog.xpnsec.com/evernote-webclipper-uxss/

    2012 Opera UXSS in Data URI Schema

    • https://labs.detectify.com/2012/10/05/universal-xss-in-opera/

    Twitter, Facebook