It is possible to read a x-domain URL after a redirect using perfomance.getEntries() if the page can be iframed.
The issue is affecting ALL current browsers (Chrome, FF and IE). Update: For specific Firefox and Chrome versions, click.
Steps:
performance entry is sethistory.back()performance is setIt take a few seconds, anyway the delay can be reduced.
http://demo.vwzq.net/php/token_redirect.php redirected to ....