XSS on Google Search - Sanitizing HTML in The Client?

An actual XSS on by Masato Kinugawa. It abuses a parsing differential between a JavaScript enabled and disabled context. The fix: https...
Back to Top