Does this JavaScript run in the same origin as the Google domain? Surely this is just an open redirect rather than xss?
The server response probably injected the “continue” parameter into a <meta http-equiv=“refresh” content=”0: url=…” />. Google’s bug bounty team likely would have adjusted the reward downward if it was not an XSS.
So I tried placing there continue=javascript:alert(document.domain), and… It works!
What do you think document.domain returns in this case?
It's commonly used as a placeholder in an alert-box XSS PoC. Weaponising this into an actual exploit could have been a fetch(), css inclusion, or enumerating localstorage.
says the article. If you disagree, could you elaborate why?