Yeah, https://xsleaks.dev tracks most of the known ways to leak cross-origin data.
56 karma · joined December 11, 2015
Here's the PoC I did: https://www.youtube.com/watch?v=0oega6C5SF0
And the mitigation I proposed was from this: http://i.imgur.com/8m6UdiC.png
To this: http://i.imgur.com/turRAdc.png
A few months ago Google fixed a vulnerability on the inline installation. It was possible to start a install on the attacker's website and then redirect the page to an arbitrary one. This would confuse the user, making him believe that the install came from the arbitrary page.
Here is the PoC if anyone is interested (CVE-2016-1640): https://www.youtube.com/watch?v=f_9ObDqBoo8