Adobe Flash Player Security Bypass (APSB16-18: CVE-2016-4139; CVE-2016-4139)

When calling window location toString() or comparing window location toString is called an attacker can return arbitrary values. An attacker can make the applet believe that it is embedded inside the hosting page, by overriding window location toString. Hence, an attacker can call any method that is exposed on the SWF script to same domain JavaScript.

Leave a Reply