Blumira research team has discovered an alternative attack vector in the Log4j vulnerability that relies on a basic Javascript WebSocket connection to trigger the RCE locally via drive-by compromise.
https://www.securitymagazine.com/articles/96766-researchers-discover-alternative-local-attack-vector-in-log4j