url with a leading NULL byte can bypass cross origin protection. https://code.google.com/p/chromium/issues/detail?id=37383 Universal XSS in frame elements handling https://code.google.com/p/chromium/issues/detail?id=143439 Pwnium UXSS variation https…