Security Advisory

CVE-2023-25729

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-06-02 00:00:00
Last updated 2025-01-10 17:35:40
Assigner mozilla
State PUBLISHED

Description

Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user interaction via <code>ExpandedPrincipals</code>. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.