Mozilla Foundation Security Advisory 2016-66

Location bar spoofing via data URLs with malformed/invalid mediatypes

Announced
August 2, 2016
Reporter
Firas Salem
Impact
Low
Products
Firefox
Fixed in
  • Firefox 48

Description

Security researcher Firas Salem reported that decoding url-encoded values in data: urls for display leads to potential spoofing in the Location bar by using non-ASCII and emoji characters in a data: url's mediatype. This issue could result in the wrong URL being displayed as a location, which can mislead users to believe they are on a different site than the one loaded.

References