The security patch for the recently disclosed cross-site scripting (XSS) vulnerability in Branch.io has introduced another similar XSS vulnerability. The vulnerability was disclosed a few days ago by the researchers at vpnMentor who explained that an attacker could have been exploited them to access Tinder users profiles. The fix for the second vulnerability was still vulnerable to a third vulnerability, using the very same payload as in the first report. The flaw recently introduced is no longer pure DOM-based XSS, but the researchers confirmed it works more or less in the same way.”]
Source: https://securityaffairs.co/wordpress/77301/hacking/branch-io-xss-flaw-2.html

