A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1783504 | issue tracking permissions required |
https://www.mozilla.org/security/advisories/mfsa2024-01/ | release notes vendor advisory |