Skip to content

Instantly share code, notes, and snippets.

View deryilz's full-sized avatar
😃
chilling

Derin Eryilmaz deryilz

😃
chilling
View GitHub Profile
/*
this is a proof-of-concept for CVE-2023-4369, which affected ChromeOS in version 115.0.5790.98
an extension with the "downloads" permission could run this code to access and modify your Documents/Downloads/Pictures
read more at https://derineryilmaz.com/blog/cve-2023-4369/
*/
function toXss(fileUrl) {