Same Origin Policy Bypass in Samsung Internet Browser
CVE-2017-17859
6.1MEDIUM
What is CVE-2017-17859?
The Samsung Internet Browser version 6.2.01.12 contains a vulnerability that allows remote attackers to bypass the Same Origin Policy. This can lead to User Experience Spoofing (UXSS) attacks, enabling attackers to access sensitive information by exploiting IFRAME elements embedded within XSLT data in MHTML files. Affected JavaScript code does not align its document.domain value with the hosting domain, instead linking it to arbitrary URLs present in the MHTML content, allowing for the execution of malicious scripts without proper restrictions.