Top 10 winner
Cross-Site Leaks
The browser HTTP cache answers cross-site questions: evict a resource with a POST or an overlong Referer, make the victim load a target page, then re-probe to see whether it got cached. That reveals whether the page requested a given resource, leaking group membership, search hits and other private state; partitioned caches and SameSite cookies mitigate it.
Record
- Researcher
- @sirdarckcat
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of @sirdarckcat, first published at the original source. Preserved copies are kept so the citation survives its host.