logo

It's 2024 and we're just getting round to stopping browsers insecurely accessing 0.0.0.0

ID: 7fcc06aa-3158-5735-a00e-1e3adb06e9e6

STIX ID: report--7fcc06aa-3158-5735-a00e-1e3adb06e9e6

Feed Name: The Register (Security)

Threat Score
55/100

Date Published: 2024-08-09

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

A long-standing browser security flaw, dubbed "0.0.0.0 Day," allows malicious webpages to send requests to 0.0.0.0:<port> and reach services on a user's machine (reported for macOS and Linux), effectively bypassing CORS and Private Network Access protections; Oligo Security demonstrated a PoC accessing a localhost service via 0.0.0.0, vendors are rolling out mitigations in Chromium and WebKit, while Firefox has not yet implemented a full fix.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.