EIP-2026-104488
PRE-CVEWebKit - 'ContainerNode::parserRemoveChild' Universal Cross-Site Scripting
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104488. PoCs published by Google Security Research.
AI-analyzed exploit summary This PoC exploits a use-after-free vulnerability in Chromium's ContainerNode::parserRemoveChild by manipulating subframe detachment and reattachment during a focus event. The exploit triggers arbitrary JavaScript execution via an iframe with a javascript: URL.
Description
WebKit - 'ContainerNode::parserRemoveChild' Universal Cross-Site Scripting
Exploits (1)
This PoC exploits a use-after-free vulnerability in Chromium's ContainerNode::parserRemoveChild by manipulating subframe detachment and reattachment during a focus event. The exploit triggers arbitrary JavaScript execution via an iframe with a javascript: URL.