FINDING · EVALUATION

Chrome's non-standard behavior of firing an onload event for any HTTP 200 OK response regardless of MIME type—combined with its enforcement of X-Content-Type-Options: nosniff—allows the script tag to probe reachability of arbitrary non-image URLs, a measurement capability unavailable in other browsers that attempt to execute fetched content as JavaScript and thus pose an XSS risk.

From 2015-burnett-encoreEncore: Lightweight Measurement of Web Censorship with Cross-Origin Requests · §4.3.2, Table 1 · 2015 · SIGCOMM

Implications

Tags

techniques
measurement-platform

Extracted by claude-sonnet-4-6 — review before relying.