An attack can use a blob URL and script to spoof an arbitrary address bar URL prefaced by blob: as the protocol, leading to user confusion and further spoofing attacks.
An attack can use a blob URL and script to spoof an arbitrary address bar URL prefaced by blob: as the protocol, leading to user confusion and further spoofing attacks.
https://www.mozilla.org/en-US/security/advisories/mfsa2017-05/#CVE-2017-5415 https://bugzilla.mozilla.org/show_bug.cgi?id=1321719