Chained attack (phishing + fullscreen + redirect)EMBEDDED

Reproduce a chain that shows fake fullscreen UI, captures credentials, then top-redirects to reduce suspicion.

Behavior by sandbox policy
PolicyExpected result
No sandboxworks
sandbox="allow-scripts"partial
sandbox="" (strictest)blocked
Embed snippet

This snippet uses the dedicated embed page. Paste it into your own service and check rendering or blocking behavior.

The current snippet has no sandbox restrictions. Use it to observe behavior, not as a production default.
<iframe src="https://xss-playground.com/embed/chained-attack?lang=en" title="XSS Playground - Chained attack (phishing + fullscreen + redirect)" width="600" height="420" loading="lazy" referrerpolicy="strict-origin-when-cross-origin"></iframe>

Run

// no logs

Explanation