Collected research
Hijacking Opera's Native Page using malicious RSS payloads
Hijacking Opera’s Native Page using malicious RSS payloads
Untrusted RSS feed content is rendered in Opera's Feed Subscription Page, a native page running in a higher-privileged zone than the internet zone. Escaping that page's HTML tag whitelist and sanitiser lets a crafted feed run script there and call native functions such as opera.feeds.subscribeNative, taking control of the browser. Fixed in Opera 10.01.
Record
- Document
- Hijacking Opera’s Native Page using malicious RSS payloads
- Published by
- securethoughts.com
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of securethoughts.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .