January 22, 2026 • –––viewsWhen Self-XSS Isn’t Self Anymore: Escalating to Account Takeoverbug-bountyWriteupWebATOXSSHow chaining a self‑XSS with email HTML injection resulted in account takeover.