vulns.co
/
GKData.io MCP

BRClient and browser security · 1 min read

Safari origin confusion undermined stored media permissions

The cited researcher documents a USD 75,000 award for this reported chain.

Read the primary source BRClient and browser securityReviewed 2026-10-02

Root cause

URL parsing, origin identity, and secure-context decisions were inconsistent with the identity used for stored permissions. Defensive design should use one coherent origin model across permission enforcement.

Demonstrated impact

Unauthorized camera and microphone access under previously granted website permissions.

Lessons for review

  • Use one coherent origin model for permission enforcement.
  • Invalidate persistent consent when the underlying resource or trust context materially changes.

Award and evidence

USD 75,000Bug Bounty · Researcher Reported

One award for the reported vulnerability chain, not this amount per CVE.

Primary public sources read; individual reward, dates, and attribution reviewed. No target testing performed.

  • One reported chain, not a $75,000 award for each CVE
  • Broader project found seven bugs; source attributes this award to the camera exploit
  • The researcher's page has no explicit publication date
  • Publication date is unknown in the primary source, so recency is explicitly uncertain.

Recorded timeline

Fixed
2020-01-28explicit · Safari 13.0.5 vendor release date; the advisory entry was added February 6.

Sources and provenance

  1. Safari origin confusion undermined stored media permissions Ryan Pickren · reviewed 2026-10-02
  2. Apple security release advisory Apple · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software