Mozilla Foundation Security Advisory 2015-141

Hash in data URI is incorrectly parsed

Announced
December 15, 2015
Reporter
Abdulrahman Alqabandi
Impact
Low
Products
Firefox
Fixed in
  • Firefox 43

Description

Security researcher Abdulrahman Alqabandi reported that when a data: URI is parsed, the hash ('#') symbol is incorrectly handled, allowing for spoofing attacks. This issue could result in the wrong URI being displayed as a location, which can mislead users to believe they are on a different site than the one loaded.

References