EIP-2026-104487
PRE-CVEWebKit - 'CachedFrameBase::restore' Universal Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104487. PoCs published by Google Security Research.
AI-analyzed exploit summary This PoC exploits a race condition in FrameLoader::open where JavaScript handlers fire during frame destruction, leading to potential UXSS (Universal Cross-Site Scripting). The attack chain involves navigating frames, triggering unload events, and manipulating document states to bypass same-origin policy.
Description
WebKit - 'CachedFrameBase::restore' Universal Cross-Site Scripting
Exploits (1)
This PoC exploits a race condition in FrameLoader::open where JavaScript handlers fire during frame destruction, leading to potential UXSS (Universal Cross-Site Scripting). The attack chain involves navigating frames, triggering unload events, and manipulating document states to bypass same-origin policy.