logoalt Hacker News

ofrzetatoday at 6:00 AM1 replyview on HN

How is it wide open? Does everything go through a localhost proxy?


Replies

raframtoday at 12:40 PM

Not sure what you mean by that, but before they implemented any mitigations, it had a CORS policy that allowed requests from any origin. As far as I know, Chromium is the only browser platform that has blocked sites from connecting to localhost, so users of other browsers would be vulnerable, and so would Chrome users if they could be convinced to allow a localhost connection.