0.0.0.0 Day: Exploiting Localhost APIs From The Browser

No ratings

Presented at BSides SF 2025 by

While seemingly local, services running on localhost are accessible to the browser using a flaw we found, exposing the ports on the localhost network interface and leaving the floodgates ajar to remote network attacks. This session will dive into the 0.0.0.0 exploit research conducted by the team.