#VU17263 Permissions, Privileges, and Access Controls in Mozilla Firefox - CVE-2018-18505
Published: January 29, 2019
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to bypass imposed sandbox restrictions.
The vulnerability exists within implementation of authentication process for Inter-process Communication (IPC). This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. A remote attacker can bypass sandbox restrictions through IPC channels due to lack of message validation in the listener process.