It's 2024 and we're just getting round to stopping browsers insecurely accessing 0.0.0.0
ID: 7fcc06aa-3158-5735-a00e-1e3adb06e9e6
STIX ID: report--7fcc06aa-3158-5735-a00e-1e3adb06e9e6
Feed Name: The Register (Security)
Threat Score
A long-standing browser security flaw, dubbed "0.0.0.0 Day," allows malicious webpages to send requests to 0.0.0.0:<port> and reach services on a user's machine (reported for macOS and Linux), effectively bypassing CORS and Private Network Access protections; Oligo Security demonstrated a PoC accessing a localhost service via 0.0.0.0, vendors are rolling out mitigations in Chromium and WebKit, while Firefox has not yet implemented a full fix.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
