.
.. The attacker may access the victim’s session data whenever the victim watches the video in a new browser tab.
.
First, the attacker generates a malicious HTML file with video and other dangerous code.
. If a match is found, the file is stored under the client’s FileSystem URI.
...