The Last Writer Wins: A Chess.com Account Takeover via postMessage XSS
Chess.com's postMessage handler took SHOW_MESSAGE_MODAL from any origin and rendered a username through innerHTML. DOMPurify ran, but a placeholder-restore step pasted the raw payload back over its output, turning a same-origin XSS into an account takeover.