CVE-2023-25728 — The Content-Security-Policy-Report-Only header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe triggers a redirect. This vulnerability affects Fir — CVE Database · The Intelligence Room