Download Firefox

Firefox is no longer supported on Windows 8.1 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox is no longer supported on macOS 10.14 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2012-99

XrayWrappers exposes chrome-only properties when not in chrome compartment

Announced
November 20, 2012
Reporter
Peter Van der Beken
Impact
High
Products
Firefox, SeaMonkey, Thunderbird
Fixed in
  • Firefox 17
  • SeaMonkey 2.14
  • Thunderbird 17

Description

Mozilla developer Peter Van der Beken discovered that same-origin XrayWrappers expose chrome-only properties even when not in a chrome compartment. This can allow web content to get properties of DOM objects that are intended to be chrome-only.

In general these flaws cannot be exploited through email in the Thunderbird and SeaMonkey products because scripting is disabled, but are potentially a risk in browser or browser-like contexts in those products.

References