|
All Categories

Direct URL / Deep Link

Weight 3

Can mature content be accessed via direct URL?

Test ID: DU-01 · Learn how scoring works

Category score:3 Unprotected
Child (7)A-
3

CRITICAL VULNERABILITY: Netflix has a two-tier protection model. Kids profiles (dedicated Netflix Kids experience) block direct URL access server-side. However, standard profiles with maturity restrictions (TestChild12 TV-PG, TestTeen16 TV-14) only filter the UI layer (search/browse) - direct URL access completely bypasses maturity filtering. A child with a TV-PG-restricted standard profile can view the full DAHMER detail page including TV-MA rating, violent content descriptions, episode listings, and access the Play button. The maturity restriction on standard profiles is a UI-only filter, not a server-side access control.

Child (12)A
3

CRITICAL VULNERABILITY: Netflix has a two-tier protection model. Kids profiles (dedicated Netflix Kids experience) block direct URL access server-side. However, standard profiles with maturity restrictions (TestChild12 TV-PG, TestTeen16 TV-14) only filter the UI layer (search/browse) - direct URL access completely bypasses maturity filtering. A child with a TV-PG-restricted standard profile can view the full DAHMER detail page including TV-MA rating, violent content descriptions, episode listings, and access the Play button. The maturity restriction on standard profiles is a UI-only filter, not a server-side access control.

Teen (16)A
3

CRITICAL VULNERABILITY: Netflix has a two-tier protection model. Kids profiles (dedicated Netflix Kids experience) block direct URL access server-side. However, standard profiles with maturity restrictions (TestChild12 TV-PG, TestTeen16 TV-14) only filter the UI layer (search/browse) - direct URL access completely bypasses maturity filtering. A child with a TV-PG-restricted standard profile can view the full DAHMER detail page including TV-MA rating, violent content descriptions, episode listings, and access the Play button. The maturity restriction on standard profiles is a UI-only filter, not a server-side access control.

Category score:2 Soft Barrier
Child (7)D (capped)
1

Direct URL to Yellowstone (TV-MA) on Kids profile shows 'Please switch to a non-kids profile to view this content' with profile picker showing all profiles including Adult. Content existence is revealed and zero-auth profile switching is available directly from the block page.

Child (12)A
1

Same 'Please switch to non-kids profile' block with profile picker

Teen (16)B+
2

Direct URL to Yellowstone (TV-MA) shows full detail page with all metadata. Same as search discovery — full access to everything except playback.

Category score:2 Soft Barrier
Child (7)D (capped)
0

Direct URL to The Boys (TV-MA) detail page shows 'Age restricted video — This video is unavailable in kids profiles.' No content details exposed.

Child (12)A+
0

Same 'Age restricted video' block on direct URL

Teen (16)B+
2

Direct URL to TV-MA content shows full detail page with metadata. Playback is PIN-gated. Same behavior as search discovery.

Score key:0 = Full Block1 = Partial Block2 = Soft Barrier3 = Unprotected4 = Facilitated

Lower scores are better. 0 means the platform fully blocks the attack vector. The category score shown on each card is the worst (highest) score across all profiles.