Web Hack List

Preliminary research

DOMPurify bypass via SMIL animateTransform on Safari

AI-collected research leads through 6 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

Browsers now escape < and > in attributes during serialization, which broke nearly every DOMPurify mutation-XSS bypass. This one goes at SMIL instead: DOMPurify's default SMIL configuration combined with Safari's implementation of the animateTransform tag yields XSS against DOMPurify 3.2.6 and earlier.

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of its author, first published at the original source. Preserved copies are kept so the citation survives its host.