Open Earthw0rmJ1m opened 3 months ago
Isn't this already disabled or related to this issue or no?
Services & Features We Disable Entirely
cc @mkarolin to confirm it’s in 128
@diracdeltas, I don't have access to the related upstream issue (https://crbug.com/1300021), but according to the feature status page (https://chromestatus.com/feature/5106143060033536) it's estimated to make it to dev trial only in cr129.
@mkarolin @diracdeltas
Why not include the lan blocklist though from UBO and include it enabled by default?
Brave disables Private Network Access, and also prevents requests to localhost: https://github.com/brave/adblock-lists/blob/master/brave-lists/brave-specific.txt. We had a separate feature for localhost request permissioning (enabled in Nightly) where an allowlisted website can issue a localhost request and the user would get a permission prompt, but the plan was to combine that with PNA at some point so we haven't rolled it out beyond Nightly.
Is there an actual attack demo page?
Platforms
all
Description
0.0.0.0 Day
Links: https://vulcan.io/blog/0-0-0-0-day https://thehackernews.com/2024/08/0000-day-18-year-old-browser.html https://www.oligo.security/blog/0-0-0-0-day-exploiting-localhost-apis-from-the-browser
Tor Browser blocks outside access to localhost https://gitlab.torproject.org/tpo/applications/tor-browser/-/issues/31065
uBlockOrigin includes
Block Outsider Intrusion into LAN
in filter list https://github.com/uBlockOrigin/uAssets/blob/master/filters/lan-block.txt https://raw.githubusercontent.com/uBlockOrigin/uAssets/master/filters/lan-block.txtBrave adblock lists
(lan-block is not included)
Could the lan-block be included with brave-sheilds list and enabled by default till chrome patches it in Chromium 128