Reverse Tabnabbing in HFS - #VU127491

 

Reverse Tabnabbing in HFS - #VU127491

Published: April 24, 2026


Vulnerability identifier: #VU127491
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-1022
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct phishing attacks.

The vulnerability exists due to use of web link to untrusted target with window.opener access in the HFS web link feature when opening an added external web link in a new tab. A remote attacker can compromise or control the linked external page to replace the original HFS tab with a phishing page to conduct phishing attacks.

Only users on browsers without the browser-level protection remain vulnerable.


Affected software

HFS

Remediation

Install security update from vendor's website.

HFS - update to 0.57.10

External References

Related Security Bulletins