Why would Same-Origin Policy (SOP) allow the script https://…
Why would Same-Origin Policy (SOP) allow the script https://evil.com/malicious.js to run if the user had the browser opened to https://mybank.com/accounts.php?
Why would Same-Origin Policy (SOP) allow the script https://…