Permissions Policy Header Not Set
- Risk:
Low
- Type:
- Passive
- CWE:
- CWE-693
- Summary
Permissions Policy Header is an added layer of security that helps to restrict from unauthorized access or usage of browser/client features by web resources. This policy ensures the user privacy by limiting or specifying the features of the browsers can be used by the web resources. Permissions Policy provides a set of standard HTTP headers that allow website owners to limit which features of browsers can be used by the page such as camera, microphone, location, full screen etc.
- Solution
Ensure that your web server, application server, load balancer, etc. is configured to set the Permissions-Policy header.
- References
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Permissions-Policy
https://developer.chrome.com/blog/feature-policy/
https://scotthelme.co.uk/a-new-security-header-feature-policy/
Microsoft warns of Windows smart card auth issues after October updates
Analysing ClickFix: 3 Reasons Why Copy/Paste Attacks Are Driving Security Breaches
131 Chrome Extensions Caught Hijacking WhatsApp Web for Massive Spam Campaign
AWS outage crashes Amazon, Prime Video, Fortnite, Perplexity and more
AWS outage crashes Amazon, PrimeVideo, Fortnite, Perplexity and more
MSS Claims NSA Used 42 Cyber Tools in Multi-Stage Attack on Beijing Time Systems
TikTok videos continue to push infostealers in ClickFix attacks
Experian fined $3.2 million for mass-collecting personal data
Europol Dismantles SIM Farm Network Powering 49 Million Fake Accounts Worldwide
CVE-2025-59230 Microsoft Windows Improper Access Control Vulnerability
CVE-2025-6264 Rapid7 Velociraptor Incorrect Default Permissions Vulnerability
CVE-2016-7836 SKYSEA Client View Improper Authentication Vulnerability
CVE-2017-3881 Cisco IOS and IOS XE Remote Code Execution Vulnerability
CVE-2021-43226 Microsoft Windows Privilege Escalation Vulnerability
CVE-2025-47827 IGEL OS Use of a Key Past its Expiration Date Vulnerability
CVE-2007-0671 Microsoft Office Excel Remote Code Execution Vulnerability
CVE-2018-7600 Drupal Core Remote Code Execution Vulnerability
CVE-2023-20273 Cisco IOS XE Web UI Command Injection Vulnerability
Free online web security scanner