Preliminary research
The Last Writer Wins: A Chess.com Account Takeover via postMessage XSS
AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.
A Chess.com postMessage handler accepted foreign-origin state. Its HTML wrapper removed diagram comments before DOMPurify, then restored them into attacker-placed placeholder tokens inside attributes, creating XSS. The account-takeover example depends on an authenticated SSO-created account that can set its first password without an old one.
Record
- Researcher
- XENOPS Research
- Published by
- XENOPS
- Date
In the archive
Related sources
- Earlier sanitizer integration case (2023)
- Earlier placeholder-collision fix (2020)
- Earlier remove-sanitize-restore example (June 2026)
Tags
This page is the archive's own catalogue record. The research is the work of XENOPS Research, first published at the original source. Preserved copies are kept so the citation survives its host.