I'm shocked this attack works. I thought the last 15 years of browser dev were largely isolating domains from each other to prevent cross-site attacks, and introducing consent flows for little used and/or dangerous platform features.
Running JS inside an image format sounds like a thing they could add permissions for (or a click-to-play overlay), especially if it can talk to other sites.
Comments
I'm shocked this attack works. I thought the last 15 years of browser dev were largely isolating domains from each other to prevent cross-site attacks, and introducing consent flows for little used and/or dangerous platform features.
Running JS inside an image format sounds like a thing they could add permissions for (or a click-to-play overlay), especially if it can talk to other sites.