fix(chromium): filter WebSocket handshakes against the outbound policy

This commit is contained in:
Julien Neuhart
2026-08-12 20:36:32 +02:00
parent 357c3b4a59
commit dc7c68152c
13 changed files with 324 additions and 2 deletions

View File

@@ -0,0 +1,20 @@
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8" />
<title>WebSocket SSRF</title>
</head>
<body>
<h1>WebSocket SSRF</h1>
<script type="application/javascript">
// Both targets resolve to non-public addresses, so CHROMIUM_DENY_PRIVATE_IPS
// must block them. Unlike fetch/XHR/sub-resources, a WebSocket handshake is
// never surfaced as a Fetch.requestPaused event, so it currently escapes the
// outbound filter entirely.
// 127.0.0.1 -> loopback
// 169.254.169.254 -> link-local (cloud metadata)
new WebSocket("ws://127.0.0.1:9999/ssrf-websocket");
new WebSocket("ws://169.254.169.254:80/ssrf-websocket");
</script>
</body>
</html>