logo

'0.0.0.0 Day' Flaw Puts Chrome, Firefox, Mozilla Browsers at RCE Risk

ID: 8c81c30a-3411-5271-9bb3-7b231bf94fec

STIX ID: report--8c81c30a-3411-5271-9bb3-7b231bf94fec

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-08-08

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Researchers at Oligo Security disclosed a browser flaw called "0.0.0.0 Day" that lets malicious web pages send requests to services on 0.0.0.0/localhost—bypassing CORS and, in some cases, Private Network Access—allowing attackers to probe local services and achieve arbitrary code execution via a single HTTP request; proof-of-concept exploits were demonstrated across Chromium, Safari, and Firefox (including use in ShadowRay and related campaigns), vendors have rolled out patches blocking 0.0.0.0, and mitigations include enforcing PNA headers, verifying HOST headers, using HTTPS, and adding local authorization and CSRF protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.