-
Notifications
You must be signed in to change notification settings - Fork 3.1k
Closed
Labels
addition/proposalNew features or enhancementsNew features or enhancementsnormative changesecurity/privacyThere are security or privacy implicationsThere are security or privacy implicationstopic: custom protocols
Description
Currently, spec allows use of custom protocols in sandboxed iframe. Which could be used to escape sandbox (see https://www.brokenbrowser.com/abusing-of-protocols/) or launch application from sandboxed iframe (mailto:, acrobat:, etc). I think custom protocols should be disabled in sandboxed iframe.
Related bugs:
https://bugzilla.mozilla.org/show_bug.cgi?id=1322925
https://bugs.chromium.org/p/chromium/issues/detail?id=329000
Metadata
Metadata
Assignees
Labels
addition/proposalNew features or enhancementsNew features or enhancementsnormative changesecurity/privacyThere are security or privacy implicationsThere are security or privacy implicationstopic: custom protocols