Unpreventable top-level navigation
Package
Affected versions
>= 8.0.0-beta.0, < 8.5.1
      >= 9.0.0-beta.0, < 9.3.0
      >= 10.0.0-beta.0, < 10.0.1
  Patched versions
8.5.1
      9.3.0
      10.0.1
  Description
        Reviewed
      Oct 6, 2020 
    
  
        Published to the GitHub Advisory Database
      Oct 6, 2020 
    
  
        Published by the National Vulnerability Database
      Oct 6, 2020 
    
  
        Last updated
      Feb 1, 2023 
    
  
Impact
The
will-navigateevent that apps use to prevent navigations to unexpected destinations as per our security recommendations can be bypassed when a sub-frame performs a top-frame navigation across sites.Patches
11.0.0-beta.110.0.19.3.08.5.1Workarounds
Sandbox all your iframes using the
sandboxattribute. This will prevent them creating top-frame navigations and is good practice anyway.For more information
If you have any questions or comments about this advisory:
References