XSS on internal: privileged origin through reader mode