Skip to content
October 1, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • Technique
  • Talk about HTML5 local storage
  • Technique

Talk about HTML5 local storage

Do Son September 13, 2017 5 minutes read
HTML5 local storage

Browser Local Storage Overview

Introduction

cookie

A cookie is a data (usually encrypted) that some websites store on the user’s local terminal in order to identify the user’s identity and track the session.

webStorage

webStorage is one of the local storage solutions in HTML5, including sessionStorag and localStorage, the difference between the two differences in the life cycle.

websql and indexeddb

IndexedDB is a low-level API for the client to store large amounts of structured data. The API uses an index to achieve a high-performance search for the data. WebStorage is useful for storing less data, but it is not useful for storing a lot of structured data. IndexedDB provides a solution.

websql is the early storage standards, is no longer maintenance, steering indexeddb, but websql better compatibility. But indexeddb is the future, so the next main indexeddb

Four contrast

Types of Life cycle Storage size Communicate with the server Scopes scenes to be used
Cookie Generally generated by the server, you can set the expiration time, the default is to disable the browser after the failure 4k or so Can carry each time in the http header, but save too much data will bring performance problems You can set the primary domain name by .setDomain It is not recommended to store data in the cookie, if necessary, to store synchronization access to the page must be brought to the server information, such as the site user login information
localStorage Permanently saved unless cleared 5m or so Can only be stored on the browser side Subdomains are independent of each other Store some of the user status and data, ease the server pressure
sessionStorage Only the current tab page, close the browser or the new tab is empty 5m or so Can only be stored on the browser side Different tabs can not be shared It is recommended to store some of the current page refresh need to store, and do not need to leave the tab when the information left, according to this to determine whether the user to refresh, restore music video playback
indexeddb Permanently saved unless cleared A separate database does not have a size limit, but may limit the size of each Indexeddb database, such as Firefox in the user interface will only be stored for more than 50 MB size of the BLOB (binary large object) request permissions, the overall basic no size limit Can only be stored on the browser side Subdomains are independent of each other Offline application or webapp can consider using indexeddb or websql to access data

【Tip】 sessionStorage can only be shared under a tab, that is, if you open a page from the current tab page, sessionStorage data is empty. But if you restore the closed page, then chrome and firefox sessionStorage will be restored, but Safari will not.

webStorage and indexeddb compatibility

webStorage compatibility

Chrome Firefox IE Opera Safari
localStorage 4 3.5 8 10.50 4
sessionStorage 5 2 8 10.50 4

Basic browsers are supported

indexeddb compatibility

Chrome Firefox IE Opera Safari
Asynchronous API 12 [webkit] 16.0 (16.0) 4.0 (2.0) [moz] 10 【ms】 Not realized Not realized
Synchronization API Not realized Not realized Not realized Not realized Not realized

Currently poor compatibility

webStorage API

LocalStorage and sessionStorage usage are the same, the following show examples of the use of sessionStorage.

// Save the data to sessionStorage

sessionStorage.setItem ('key', 'value');
// Get data from sessionStorage
var data = sessionStorage.getItem ('key');
// remove the saved data from sessionStorage
sessionStorage.removeItem ('key');
// remove all saved data from sessionStorage
sessionStorage.clear ();
// enumerate sessionStorage methods
for (var i = 0; i <sessionStorage.length; i ++) {
var key = sessionStorage.key (i);
var value = sessionStorage.getItem (key);
}

Of course, you can also use the object to set the way to the assignment.

sessionStorage [ 'colorSetting' ] = '# a4509b' ;

sessionStorage.setItem ( 'colorSetting' , '# a4509b' );

However, the official proposal only use webStorage API (getItem, removeItem, key, length), to avoid the use of object key storage some of the defects, please click here for details

storage event

There are storage events for webStorage. When the storage changes, the storage event is triggered.
The condition here is that the data has changed, and if the current storage area is empty, even if the call to clear () will not trigger the event. Or if you set a value that is the same as the existing value by settingItem(), the event will not fire.

storage attribute

Attribute name description
key On behalf of the attribute name changes. When the clear () method is cleared after all the property name becomes null. Read only (read only).
newValue Newly added value. When executed by the clear () method or deleted by the attribute name, the value becomes null. Read only (read only).
oldValue The original value is changed to null by the clear () method or replaced by a new value. Read only.
storageArea The storage object being manipulated. Read only.
url key The URL of the document corresponding to the changed object. Read only.

The following describes the use of multi-tab page sessionStorage will use chestnuts.

The multi-tab page uses sessionStorage

In the recent use of vuejs write completely before and after the separation of the project, when doing login authentication, in the end how to store user authentication information.

Because the system security requirements are relatively high, requiring the user to close the tab when the session immediately expires, the use of cookies to save the sensitive token is not appropriate. If you use localstorage, the localstorage data is still there, and the requirements are not met.
Think only use sessionStorage.

But embarrassing is that the use of sessionStorage is no longer able to share more pages. Each time you open a new tab, it will jump to the login page, the user experience is not friendly.

In simple terms, if the new tab if there is no sessionStorage data, it will trigger a localstorage modify events, then in the existing label received this event, it will be the current page sessionStorage data stored in localstorage, but immediately Removed. But in the new tab will listen to the event, you can get to the sessionStorage data, which will ensure that the new tab page can also get sessionStorage, but also to ensure that localstorage does not exist token information.

 function () {

if (! sessionStorage.length) {
// If the current page does not have sessionStorage data, it triggers an event.
localStorage.setItem ( 'getSessionStorage' , Date .now ());
};
window .addEventListener ( 'storage' , function ( event ) {
//console.log('storage event ', event);
if (event.key == 'getSessionStorage' ) {
// already existing tab page After receiving the event, talk sessionStorage data to localstorage and remove it immediately.
localStorage.setItem ( 'sessionStorage' , JSON .stringify (sessionStorage));
localStorage.removeItem ( 'sessionStorage' );
} else if (event.key == 'sessionStorage' &&! sessionStorage.length) {
// The new tab will listen to the event here, through the newValue this property is stored in the localstorage sessionStorage data
var data = JSON .parse (event.newValue), value;
console .log (data, "111" );
for (key in data) {
sessionStorage.setItem (key, data [key]);
}
}
});

}) ();

IndexedDB

Usage is not as simple as sessionStorage, but the following two articles on the basic indexeddb usage are relatively clear. No extra finishing.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Tags: HTML5 local storage

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2025-41753CVSS 9.3
    The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient...
    📅 Updated: Oct 1, 2026
  • CVE-2026-92966CVSS 9.1
    The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable...
    📅 Updated: Oct 1, 2026
  • CVE-2026-82824CVSS 9.3
    Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access,...
    📅 Updated: Oct 1, 2026
  • CVE-2026-82825CVSS 9.3
    Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated...
    📅 Updated: Oct 1, 2026
  • CVE-2026-82827CVSS 9.3
    Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT...
    📅 Updated: Oct 1, 2026
  • CVE-2026-82829CVSS 9.3
    Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain...
    📅 Updated: Oct 1, 2026
  • CVE-2026-76142CVSS 9.3
    Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows...
    📅 Updated: Oct 1, 2026
  • CVE-2026-102425CVSS 9.5
    Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa...
    📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.