Skip to content
This repository has been archived by the owner on May 10, 2024. It is now read-only.

[hackerone] javascript: security isssue #2463

Closed
diracdeltas opened this issue Apr 13, 2020 · 2 comments · Fixed by #2550
Closed

[hackerone] javascript: security isssue #2463

diracdeltas opened this issue Apr 13, 2020 · 2 comments · Fixed by #2550

Comments

@diracdeltas
Copy link
Member

diracdeltas commented Apr 13, 2020

see https://hackerone.com/reports/846152 or ask yan for details

Test Plan

Specified here: #2550

@diracdeltas
Copy link
Member Author

discussed in Slack, decided solution was just to strip javascript: from the URL bar when pasting

@srirambv
Copy link
Contributor

Verification passed on iPhone XR with iOS 13.5 running 1.17(20.5.21.17)


Verification passed on iPhone 7+ with iOS 13.4.5 running 1.17(20.5.21.17)


Verification passed on iPhone 6 with iOS 12.4.5 running 1.17(20.5.21.17)


Verification passed on iPad Pro with iOS 13.4.5 running 1.17(20.5.21.17)


Verification passed on iPad Pro with iOS 12.4.5 running 1.17(20.5.21.17)


# for free to subscribe to this conversation on GitHub. Already have an account? #.