Nytro Posted November 29, 2020 Report Posted November 29, 2020 In this video, Filedescriptor introduces his Chrome Extension "Untrusted Types" that abuses Trusted Types and demonstrates how easy it is to find DOMXSS using it. Untrusted Types GitHub repo: https://github.com/filedescriptor/unt... Google's Firing Range: https://public-firing-range.appspot.com/ Prompt(1) to win: https://prompt.ml Quote