We've written a new guide on XS-Leaks:
https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/XS-Leaks
Many thanks to @freddy, Hamish Willee, @MartinaKraus11, and @terjanq for your reviews and collaboration. #websecurity
Cross-site leaks (XS-Leaks) - Security on the web | MDN
Cross-site leaks (also called XS-Leaks) are a class of attack in which an attacker's site can derive information about the target site, or about the user's relationship with the target site, by using web platform APIs that enable sites to interact with one another. The information leaked could include, for example:
