An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.
[ { "events": [ { "introduced": "0" }, { "fixed": "52.0" } ] } ]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5415.json"