Metro by T-Mobile — callback_uri DOM XSS → cookie theft → authenticated request

Bug bounty PoC (T-Mobile Bugcrowd). Open this page as ?id=<your-webhook.site-UUID>. A signed-in Metro victim's JavaScript-readable cookies are read cross-origin, sent to your webhook.site inbox, and assembled into a ready-to-replay authenticated request.

Authenticated HTTP request (copy/paste → Caido / Burp / curl)

Waiting for cookies…

Cookie header only

Waiting for cookies…

JavaScript-readable cookies (structured)

Waiting for JavaScript-readable cookies…