Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wph3-4v72-8x34

Опубликовано: 22 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.

Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.

EPSS

Процентиль: 10%
0.00036
Низкий

7.5 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

Using a javascript: URI with a setTimeout race condition, an attacker can execute unauthorized scripts on top origin sites in urlbar. This bypasses security measures, potentially leading to arbitrary code execution or unauthorized actions within the user's loaded webpage. This vulnerability affects Focus for iOS < 122.

EPSS

Процентиль: 10%
0.00036
Низкий

7.5 High

CVSS3

Дефекты

CWE-362