#VU100952 Security features bypass in Mozilla Firefox and Firefox ESR - CVE-2024-11694
Published: November 26, 2024 / Updated: December 16, 2024
Mozilla Firefox
Firefox ESR
Mozilla
Description
The vulnerability allows a remote attacker to bypass implemented CSP.
The vulnerability exists due to Enhanced Tracking Protection's Strict mode allows a CSP frame-src bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. A remote attacker can masquerade malicious frames as legitimate content.