CVE-2023-33244

Improper Access Control for browser APIs in Obsidian (ObsidianにおけるブラウザAPIに対するアクセス制御不備)

Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web page.

Disclosure Date

2023/05/19

Credit

RyotaK

Back