WebRTC Data Channels Enable CSP-Agnostic Payment Skimming on E-Commerce Platforms
Attackers are deploying payment skimmers that abuse WebRTC data channels to receive malicious payloads and exfiltrate stolen card data, successfully circumventing Content Security Policy controls that block traditional HTTP-based exfiltration vectors.