18-year-old security flaw in Firefox and Chrome exploited in attacks
ID: e7d16a14-52c7-53e9-8fd5-35b6a35bd4cc
STIX ID: report--e7d16a14-52c7-53e9-8fd5-35b6a35bd4cc
Feed Name: Bleeping Computer
Threat Score
**Executive summary:** The report details the "0.0.0.0 Day" vulnerability — a gap in browser handling of the 0.0.0.0 wildcard address that allows public websites to reach local services on Linux and macOS, bypassing CORS and PNA protections; it is actively exploited in campaigns (ShadowRay, Selenium-targeting, ShellTorch) to perform unauthorized configuration changes, remote code execution, and reconnaissance, and browser vendors are implementing phased mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
