1mo ago · hacker-news
A critical session isolation vulnerability in Writer, an enterprise AI platform, dubbed WriteOut, allowed attackers to hijack user accounts across tenants by exploiting the live preview feature. By tricking a logged-in user into clicking a malicious preview link, attackers could steal session cookies and gain full access to the victim's account, including sensitive data and administrative privileges. The vulnerability bypassed input filters by fetching and executing remote malicious scripts within a sandboxed environment.