Mozilla Foundation Security Advisory 2016-66
Location bar spoofing via data URLs with malformed/invalid mediatypes
- Announced
- August 2, 2016
- Reporter
- Firas Salem
- Impact
- Low
- Products
- Firefox
- Fixed in
-
- Firefox 48
Description
Security researcher Firas Salem reported that decoding url-encoded
values in data:
urls for display leads to potential spoofing in the Location
bar by using non-ASCII and emoji characters in a data:
url's mediatype. This
issue could result in the wrong URL being displayed as a location, which can mislead users
to believe they are on a different site than the one loaded.