Malvertisers Exploited WebKit 0-Day to Redirect Browser Users to Scam Sites

In The Hacker News - Original news source is thehackernews.com by Blog Writer

Post Sharing
A malvertising group known as “ScamClub” exploited a zero-day vulnerability in WebKit-based browsers to inject malicious payloads that redirected users to fraudulent websites gift card scams.
The attacks, first spotted by ad security firm Confiant in late June 2020, leveraged a bug (CVE-2021–1801) that allowed malicious parties to bypass the iframe sandboxing policy in the browser engine that