Google Tag Manager Can Bypass CSP and WAF Protections, Researcher Warns

Security researcher Ryan Chaplin, writing for Raxis, found that misconfigured Content Security Policies using unsafe directives for Google Tag Manager can be exploited to bypass both CSP protections and Cloudflare WAF defenses. The vulnerability stems from developers allowing googletagmanager.com as a trusted script source, which attackers can abuse by hosting malicious JavaScript on Google's own infrastructure. Chaplin demonstrated the risk using a classic reflected XSS vulnerability, showing how an attacker could execute unauthorized scripts even on sites with active security policies. Google acknowledged the findings through its bug bounty program, awarding Chaplin an honorable mention, though the issue is not exclusive to Google Tag Manager and affects any platform permitting user-hosted content with unsafe directives. Organizations are advised to adopt strict nonce-based or hash-based CSP configurations and review third-party script permissions to reduce exposure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in