Mozilla Foundation Security Advisory 2015-25
Local files or privileged URLs in pages can be opened into new tabs
- Announced
- February 24, 2015
- Reporter
- Armin Ebert
- Impact
- Moderate
- Products
- Firefox, SeaMonkey
- Fixed in
-
- Firefox 36
- SeaMonkey 2.33
Description
Security researcher Armin Ebert reported that opening hyperlinks on a page with the mouse and specific keyboard key combinations could allow a Chrome privileged URL to be opened without context restrictions being preserved. This could also allow for local files or resources from a known location to be opened with local privileges, bypassing security protections.