Detecting browser...
CategoryURL Handling
VisibilityPublic
TypeJS
CharsetUTF-8
Template used:
if (new URL('https://www.example.com/$[chr]evil.com').host=='evil.com') {0x0D
log('"https://www.example.com/$[chr]evil.com" -> "evil.com"')0x0D
}0x0D
0x0D
if (new URL('https://www.example.com$[chr]evil.com').host=='evil.com') {0x0D
log('"https://www.example.com$[chr]evil.com" -> "evil.com"')0x0D
}Sample payloads
if (new URL('https://www.example.com/0x00evil.com').host=='evil.com') {0x0D
alert('"https://www.example.com/0x00evil.com" -> "evil.com"')0x0D
}0x0D
0x0D
if (new URL('https://www.example.com0x00evil.com').host=='evil.com') {0x0D
alert('"https://www.example.com0x00evil.com" -> "evil.com"')0x0D
}Fuzz results
Chrome 148.0.0.0 desktop Windows NT 10.0
Updated15 Mar 2026
Found 1 result
Loading...
Firefox 148.0 desktop Windows NT 10.0
Updated23 Feb 2026
Found 1 result
Loading...
Firefox 147.0 desktop Linuxolder version
Updated1 Feb 2026
Found 1 result
Loading...
Microsoft Edge 145.0.0.0 desktop Windows NT 10.0
Updated18 Feb 2026
Found 1 result
Loading...