Yes and no.
No, because it cannot be used as an exploit.
Yes, because it allows you to read the address of the "top" object.
Consider it similar to the CSS link-color hack to read the past browsing history of a user.
No, because it cannot be used as an exploit.
Yes, because it allows you to read the address of the "top" object.
Consider it similar to the CSS link-color hack to read the past browsing history of a user.
I assume this same method could be used by people with less savory goals, but this company isn't reporting the security flaws in browsers that let them do this as it would make things more difficult for their business.
I probably wouldn't go around telling everyone if it was me.