'0.0.0.0 Day' Flaw Puts Chrome, Firefox, Mozilla Browsers at RCE Risk
ID: 8c81c30a-3411-5271-9bb3-7b231bf94fec
STIX ID: report--8c81c30a-3411-5271-9bb3-7b231bf94fec
Feed Name: Dark Reading
Date Published: 2024-08-08
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Researchers at Oligo Security disclosed a browser flaw called "0.0.0.0 Day" that lets malicious web pages send requests to services on 0.0.0.0/localhost—bypassing CORS and, in some cases, Private Network Access—allowing attackers to probe local services and achieve arbitrary code execution via a single HTTP request; proof-of-concept exploits were demonstrated across Chromium, Safari, and Firefox (including use in ShadowRay and related campaigns), vendors have rolled out patches blocking 0.0.0.0, and mitigations include enforcing PNA headers, verifying HOST headers, using HTTPS, and adding local authorization and CSRF protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
