Hacker News new | past | comments | ask | show | jobs | submit login
Firefox – Same-Origin Policy Bypass (CVE-2015-7188) (bentkowski.info)
32 points by cujanovic on July 6, 2016 | hide | past | favorite | 5 comments




Yes, in Firefox 42.

> However, I think that this bug is interesting from a purely technical standpoint, hence I decided to share.


It was fascinating, and a good reason not to copy and paste code when you can prevent it.


Title seems misleading. The same-origin bypass is via Flash. The Firefox portion is having a funky URL/hostname, which Flash then uses (edit: mis-parses).


Very interesting exploit. I wonder what else is affected by IP addresses parsing issues.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: