jigbrowser+ for iOS Same Origin Policy Security Bypass Vulnerability
BID:70146
Info
jigbrowser+ for iOS Same Origin Policy Security Bypass Vulnerability
| Bugtraq ID: | 70146 |
| Class: | Design Error |
| CVE: |
CVE-2014-5318 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 25 2014 12:00AM |
| Updated: | Sep 25 2014 12:00AM |
| Credit: | Toshiharu Sugiyama of DeNA Co., Ltd |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
jigbrowser+ for iOS Same Origin Policy Security Bypass Vulnerability
jigbrowser+ for iOS is prone to a same origin policy security-bypass vulnerability.
Attackers can exploit this issue to bypass the same-origin policy and certain access restrictions to access data, or execute arbitrary script code in the browser of an unsuspecting user in the context of another site. This could be used to steal sensitive information or launch other attacks.
jigbrowser+ for iOS is prone to a same origin policy security-bypass vulnerability.
Attackers can exploit this issue to bypass the same-origin policy and certain access restrictions to access data, or execute arbitrary script code in the browser of an unsuspecting user in the context of another site. This could be used to steal sensitive information or launch other attacks.
Exploit / POC
jigbrowser+ for iOS Same Origin Policy Security Bypass Vulnerability
Attackers may use standard tools to exploit this issue. The attacker must entice a user to visit a malicious website.
Attackers may use standard tools to exploit this issue. The attacker must entice a user to visit a malicious website.
References
jigbrowser+ for iOS Same Origin Policy Security Bypass Vulnerability
References:
References: