logo

18-year-old security flaw in Firefox and Chrome exploited in attacks

ID: e7d16a14-52c7-53e9-8fd5-35b6a35bd4cc

STIX ID: report--e7d16a14-52c7-53e9-8fd5-35b6a35bd4cc

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-08-08

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

**Executive summary:** The report details the "0.0.0.0 Day" vulnerability — a gap in browser handling of the 0.0.0.0 wildcard address that allows public websites to reach local services on Linux and macOS, bypassing CORS and PNA protections; it is actively exploited in campaigns (ShadowRay, Selenium-targeting, ShellTorch) to perform unauthorized configuration changes, remote code execution, and reconnaissance, and browser vendors are implementing phased mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.