[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Web Extensions could access pre-redirect URL when their context menu was triggered by a user - CVE-2021-43532 (Mac OS)

ID: oval:org.secpod.oval:def:80164Date: (C)2022-05-19   (M)2023-11-19
Class: VULNERABILITYFamily: macos




When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element clicked. If the Web Extension lacked the WebRequest permission for the hosts involved in the redirect, this would be a same-origin-violation leaking data the Web Extension should have access to. This was fixed to provide the pre-redirect URL.

Platform:
Apple Mac OS 14
Apple Mac OS 13
Apple Mac OS 12
Apple Mac OS X 10.11
Apple Mac OS X 10.12
Apple Mac OS X 10.13
Apple Mac OS X 10.14
Apple Mac OS X 10.15
Apple Mac OS 11
Product:
Mozilla Firefox
Reference:
CVE-2021-43532
CVE    1
CVE-2021-43532

© SecPod Technologies