Description
Detects web pages that abuse the referrerpolicy attribute on prefetched links to exfiltrate URL query parameters, the technique tied to CVE-2025-4664. Cyberattackers can capture sensitive values, such as password reset tokens, that a victim site appends to a link before the browser sends the request cross-origin.