
DOM-Based XSS on YouTube Services Directory
A detailed walkthrough on how I chained two different tricks (iframe srcdoc and a CSP bypass) to achieve XSS. Then an explanation of how Google patched the vulnerable code.

A detailed walkthrough on how I chained two different tricks (iframe srcdoc and a CSP bypass) to achieve XSS. Then an explanation of how Google patched the vulnerable code.