Parent token / network theft attemptsEMBEDDED

Probe the boundary around parent JWTs, storage, and in-flight network requests from inside an iframe.

Behavior by sandbox policy
PolicyExpected result
No sandboxpartial
sandbox="allow-scripts"partial
sandbox="" (strictest)blocked
Embed snippet

This snippet uses the dedicated embed page. Paste it into your own service and check rendering or blocking behavior.

The current snippet has no sandbox restrictions. Use it to observe behavior, not as a production default.
<iframe src="https://xss-playground.com/embed/token-exfil?lang=en" title="XSS Playground - Parent token / network theft attempts" width="600" height="420" loading="lazy" referrerpolicy="strict-origin-when-cross-origin"></iframe>

Run

// no logs

Explanation