logo

Persisting XSS With IFrame Traps

ID: 97f17754-2a54-582d-bf84-ddfd26f319f3

STIX ID: report--97f17754-2a54-582d-bf84-ddfd26f319f3

Feed Name: TrustedSec blog

Threat Score
50/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This blog post details a proof-of-concept 'iframe trap' for extending XSS payload lifetime by embedding the target page in an iframe, copying the iframe URL into the browser address bar via history.replaceState, and using sessionStorage plus event handlers (and context-menu suppression) to persist and reinitialize the trap; the technique increases the window for data exfiltration or credential capture but the provided PoC contains no malicious payload and there is no evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.