Microsoft Internet Explorer, possibly 8, does not properly restrict focus changes, which allows remote attackers to read keystrokes via "cross-domain IFRAME gadgets."
- https://bugzilla.mozilla.org/show_bug.cgi?id=552255
No PoCs found on GitHub currently.