Two Bypasses for Chrome's Sanitizer API › Searchlight Cyber
Source: Slcyber
Published:
<p>The Sanitizer API arrived with much fanfare in both Chrome 146 and Firefox 148 just a few months ago. The API provides two new ways to set HTML safely from within javascript; the default mode:</p> <p>And the more customizable mode:</p> <p>The most permissive mode for this new API is the empty con