If you're currently using Microsoft's Internet Explorer, whatever you type in the browser's address bar can be leaked to web pages.
The issue was revealed by security researcher Manuel Caballero on Tuesday on the website Broken Browser.
When a script is executed inside an object-html tag, the location object will get confused and return the main location instead of its own. To be precise, it will return the text typed in the address bar so whatever a user types will be accessible to the attacker.
This means that websites can run a simple script to learn what users type in the Internet Explorer address bar while the user is on any website that uses the script.
You can check the poc below to see if the version of Internet Explorer you are using, or any other browser, is affected by the issue.
https://www.cracking.com.ar/demos/ieaddressbarguess/
Just type whatever comes to mind in the Internet Explorer address bar while you're on the page, then press the Enter key.
The website will interrupt the loading process, and display what you typed.
See also the demo video
