← Back to release summary

XSS Auditor blocks by default

Category
Security
Type
New or changed feature
Status
Enabled by default (Chrome 57)
Intent stage
None

Summary

Chrome's XSS Auditor should block pages by default, rather than filtering out suspected reflected XSS. Moreover, we should remove the filtering option, as breaking specific pieces of page's script has been an XSS vector itself in the past.

Standards & signals

Docs: https://msdn.microsoft.com/en-us/library/dd565647(v=vs.85).aspx

View on chromestatus.com