When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Serious bug in Internet Explorer bypasses same-origin policy

Attackers can now bypass the same-origin policy in Internet Explorer with a newly discovered vulnerability that allows them to inject malicious code into any website and steal cookies.
Image via Ars Technica

Microsoft is working to patch a vulnerability in Internet Explorer that allows attackers to bypass the same origin policy, inject malicious code into websites, and steal cookies, session and login details.

A group, known as Deusen, has published a proof-of-concept demonstrating the exploit violating the same origin policy on the Daily Mail's website, the demo injects the words "Hacked by Deusen" on the website, which means other HTML and Javascript code can be injected as well.

Microsoft has said it is "not aware of this vulnerability being actively exploited and are working on a security update." It also encouraged customers "to avoid opening links from untrusted sources and visiting untrusted sites, and to log out when leaving sites to help protect their information."

The exploit appears to use iframes to tamper with the same origin policy in IE. Once the attacker's code bypasses the policy and is injected, the code has access to sensitive information normally restricted to the target website, such as session details, cookies, and login, among other things.

Unlike other universal cross-site scripting (XSS) exploits, this malicious code doesn't have to be uploaded or hosted on the target website instead it can be hosted any where, however, as Microsoft pointed out, users would have to be lured to a malicious website containing the exploit.

Source: Ars Technica

Next Article

Windows 10 for phones brings new UI element: long tiles

Previous Article

TechSpot: 10 features Android Wear should have

12 Comments

Load the comments and join the conversation!

Read the comments, ask the editors questions, show respect and join the conversation.

Click here