Script Gadgets! Google Docs XSS Vulnerability Walkthrough @LiveOverflow
Script Gadgets! Google Docs XSS Vulnerability Walkthrough  @LiveOverflow
Uploaded July 2020 | Updated September 2026, 2 weeks ago
A very interesting cross-site scripting issue in Google Docs spreadsheets. I get a chance to talk to the bug hunter Nick, as well as Google engineers to understand both sides. How did he find it? And why did this vulnerability exist in the first place?

The video is sponsored by Google's VRP: google.com/about/appsecurity/reward-program

LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-xss/xss-in-google
Join the Hextree Discord: discord.gg/xgQpCQCpvy

Nickolay: thisisqa.com

CHAPTERS
00:00 - Introduction
00:53 - Following reproduction steps
02:13 - What is postMessage()?
03:04 - Script Gadget: the hlc() function
03:30 - Script Gadget: ui.type instantiation
04:22 - Vulnerability summary
05:12 - Nick's focus on gviz
06:47 - Script Gadget: chartType injection
08:09 - Script Gadget: drawFromUrl exploit technique
08:57 - chartType injection fix
10:13 - Code refactoring cause of XSS
11:12 - How to find ui.type option?
14:04 - What to do with ui.type Script Gadgets?
15:13 - Why does hlc() exist?!
15:40 - JSONP sandbox
17:16 - Nick's background story

SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com

WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog

#XSS #WebSecurity #LiveOverflow

(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
Script Gadgets! Google Docs XSS Vulnerability WalkthroughThe Same Origin Policy - Hacker HistoryDEF CON & Black Hat Trip 2024Why Hackers Love the Number 1,094,795,585Why MissingNo Multiplies Items!Discussing Heap Exploit Strategies for sudo - Ep. 09Introduction to Docker for CTFsWhat is a Protocol? (Deepdive)Failed DOM Clobbering Research - All The Little Things 1/2 (web) Google CTF 2020Local Root Exploit in HospitalRun SoftwareCode Review vs. Dynamic Testing explained with MinecraftHow Speedrunners Use Game Hacking Tools
LiveOverflow |

Script Gadgets! Google Docs XSS Vulnerability Walkthrough

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER