navigator.sendBeacon / fetch exfiltrationEMBEDDED

Check how data collected inside the iframe's own origin and referrer information can be sent out via sendBeacon or fetch.

Behavior by sandbox policy
PolicyExpected result
No sandboxworks
sandbox="allow-scripts"works
sandbox="" (strictest)blocked
Embed snippet

This snippet uses the dedicated embed page. Paste it into your own service and check rendering or blocking behavior.

<iframe src="https://xss-playground.com/embed/beacon-exfil?lang=en" title="XSS Playground - navigator.sendBeacon / fetch exfiltration" width="600" height="420" loading="lazy" referrerpolicy="strict-origin-when-cross-origin"></iframe>

Run

document.referrer
-
navigator.userAgent
-
// no logs

Explanation