Attacker Page — postMessage origin bypass

This page is loaded on a different origin (in a real attack, attacker.tld). Here it just demonstrates the same-origin case, but origin is never checked.

Click Steal Config to send {action:"getConfig"} to the widget without any origin check:

Result will appear here...