Mehrere Schwachstellen (CVE-2023-49899, CVE-2023-49900, CVE-2026-15916, CVE-2026-15917, CVE-2026-50148, CVE-2026-52842, CVE-2026-52843, CVE-2026-52891, CVE-2026-52893, CVE-2026-55652, CVE-2026-55805) in Policy
⚠️ CVE-Referenzen:
CVE-2023-49899
CVE-2023-49900
CVE-2026-15916
CVE-2026-15917
CVE-2026-50148
CVE-2026-52842
CVE-2026-52843
CVE-2026-52891
CVE-2026-52893
CVE-2026-55652
CVE-2026-55805
Lightpanda-io - Browser - CRITICAL - CVE-2026-52842.
A vulnerability in the Lightpanda Browser prior to version 0.3.1 allowed attackers to exploit the way the browser computes page origins. By improperly interpreting URLs, the browser treated potentially malicious URL segments as trusted origins, leading to a Complete Same-Origin Policy bypass. This flaw permitted an attacker at `attacker.com` to interact with resources intended for `victim.com`, posing significant security risks to users leveraging the browser for AI and automation tasks. The issue has been resolved in version 0.3.1, reinforcing the browser's safety for users.
Quelle: securityvulnerability.io