Executive brief
A vulnerability in early versions of Microsoft Internet Explorer and Netscape Navigator allows malicious websites to track a user's browsing activity. By using JavaScript, an attacker can monitor which other websites a person is visiting or has visited. This poses a significant privacy risk as it allows third parties to spy on a user's online behavior without their consent.
Technical details
This vulnerability, historically referred to as the 'Bell Labs vulnerability,' stems from a flaw in the JavaScript implementation of early web browsers. It allows a remote attacker to bypass certain privacy boundaries to monitor a user's web activities across different sessions or windows. The attack is delivered via a malicious webpage containing specific JavaScript code. While it does not allow for remote code execution or direct data theft from the local system, it facilitates unauthorized tracking of user navigation and browsing history. This issue affected Internet Explorer versions 3.x and 4.x, as well as Netscape versions 2.x through 4.x.
Affected products
- Microsoft Internet Explorer 3.x, 4.x
- Netscape Navigator 2.x, 3.x, 4.x
Timeline
- 1997-07-08: disclosed: Initial publication of the vulnerability details.