Ray’s local developer interface trusts a spoofable browser header as its only defence, letting a malicious webpage combine DNS rebinding with Firefox or Safari to run code on a developer’s machine.