CSP bypass: How one Chrome XSS bug took 2.5 years and an HTML spec change to fix | Heykuki News