Disclosure Date 2023/05/19

CVE-2023-33244

Improper Access Control for browser APIs in Obsidian

ObsidianにおけるブラウザAPIに対するアクセス制御不備

Credit

RyotaK

Description

Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page.

Back