AppCache is now removed from insecure contexts. AppCache is a powerful feature that allows offline and persistent access to an origin, which is a powerful privilege escalation for an XSS. This will remove that attack vector by only allowing it over HTTPS. This feature was deprecated in Chrome 67.


Part of the larger effort to remove powerful features on insecure origins: blink-dev discussion and API owner approval:!topic/blink-dev/UKF8cK0EwMI

Last updated on 2021-12-21