General: Better validation for iframe event origins (#6856)
details
- Finding IDs
- F-WEBA-POSTMSG-001
- Status
- partially likely fixed publicly (re-test needed)
- Reported via
- Telegram security contact
- Note
- public WebA commit 7e789e6 on 2026-04-17 adds isMessageFromIframe(...) checks so iframe events are accepted only from the expected iframe. caveat: outbound postMessage(..., '*') patterns may still exist, so this is tracked as partial/likely fixed pending re-test if the original issue was specifically targetOrigin='*'.
F-WEBA-POSTMSG-001: Access control. Incoming iframe messages require source/origin binding; outbound targetOrigin coverage remains unconfirmed. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-WEBA-POSTMSG-001
Security area (1seal assessment): Authorization. Incoming iframe events are bound to the intended source, restricting who can invoke the message handler. This does not establish coverage of outbound targetOrigin behavior. Reviewed 24 Sep 2026.