MyKeeta UAV — 0-click XSS → CORS → ATO

Target: uav-hk.mykeeta.com
Vulnerable component: sec-download-sdk 1.3.9
Vector: postMessage → SDK bridge → a[href] → click() → JS execution (0-click)
CORS chain: auth.mykeeta.com allows uav-hk.mykeeta.com with ACAC: true
Impact: Steal authenticated user data/tokens from auth.mykeeta.com + localStorage tokens

Stolen Data