|
|
WebKit: UXSS via ContainerNode::parserRemoveChild | |
| Project Member Reported by lokihardt@google.com, Feb 2 2017 | Back to list | |
This is a regression test from https://crbug.com/456518. ContainerNode::parserRemoveChild doesn't detach subframes unlike ContainerNode::removeChild. As a result, it could lead to UXSS. Tested on Safari 10.0.3(12602.4.8). This bug is subject to a 90 day disclosure deadline. If 90 days elapse without a broadly available patch, then the bug report will automatically become visible to the public.
,
Apr 7 2017
WebKit Tracker: https://bugs.webkit.org/show_bug.cgi?id=168490
,
May 4 2017
|
||
| ► Sign in to add a comment | ||
Status: Fixed