Mozilla Foundation Security Advisory 2012-60
Escalation of privilege through about:newtab
- Announced
- August 28, 2012
- Reporter
- Mariusz Mlynski
- Impact
- Critical
- Products
- Firefox
- Fixed in
-
- Firefox 15
Description
Security researcher Mariusz Mlynski reported that when a
page opens a new tab, a subsequent window can then be opened that can be
navigated to about:newtab
, a chrome privileged page. Once
about:newtab
is loaded, the special context can potentially be used
to escalate privilege, allowing for arbitrary code execution on the local system
in a maliciously crafted attack.