callback_uri DOM XSS → cookie theft → authenticated requestBug bounty PoC (T-Mobile Bugcrowd). Open this page as
?id=<your-webhook.site-UUID>. A signed-in Metro victim's JavaScript-readable
cookies are read cross-origin, sent to your webhook.site inbox, and assembled into a ready-to-replay
authenticated request.
Waiting for cookies…
Waiting for cookies…
Waiting for JavaScript-readable cookies…