A compromised content process could have performed session history manipulations it should not have been able to due to testing infrastructure that was not restricted to testing-only configurations. This vulnerability affects Firefox < 88.
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
Link | Tags |
---|---|
https://www.mozilla.org/security/advisories/mfsa2021-16/ | release notes vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1694727 | issue tracking permissions required vendor advisory |