Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/CENSUS/whatsapp-mitd-mitm
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/soosmile/POC