Endpoint Vulnerability

Partial same-origin-policy through setting location.host through data URI

Description

Security researcher Armin Razmdjou reported that the location.host property can be set to an arbitrary string after creating an invalid data: URI. This allows for a bypass of some same-origin policy protections. This issue is mitigated by the data: URI in use and any same-origin checks for http: or https: are still enforced correctly. As a result cookie stealing and other common same-origin bypass attacks are not possible.

Affected Products

Firefox

References

CVE-2016-2825,