Click here to download the Blitz Browser!

WPT

wpt / cors / image-tainting-in-cross-origin-iframe.sub.html

Spec: Fetch ↗

Runs: Chrome 155.0.8039.0 (wpt@ffab1bde3, 2026-09-03) | Firefox 157.0a1 (wpt@5e776f019, 2026-09-03) | Safari 251 preview (wpt@5ce815a83, 2026-08-27) | Ladybird 1.0-a9df8 (wpt@9b4cabf6d, 2026-09-03) | Servo Servo 0.6 (wpt@7e3d005d7, 2026-09-03) | Blitz a50cb8971 (wpt@a95401e4e, 2026-09-03)

View on the Blitz WPT dashboard | Open test on wpt.live | wpt.fyi

ChromeFirefoxSafariLadybirdServoBlitz
Total1/11/11/11/11/1NOT RUN
SubtestChromeFirefoxSafariLadybirdServoBlitz
An image resource that is same-origin to the top-level frame loaded in the frame is not treated as same-origin for an iframe that is cross-origin to the top-level frame, and therefore a canvas where the image is drawn gets tainted.PASSPASSPASSPASSPASS