Permissions, Privileges, and Access Controls in Mozilla Firefox - CVE-2019-11741
Published: September 3, 2019
Mozilla Firefox
Detailed vulnerability description
The vulnerability allows a remote attacker to perform UXXS attacks.
The vulnerability exists due to insufficient isolation of addons.mozilla.org and accounts.firefox.com. A remote attacker can use another vulnerability to compromise a sandboxed process and use it to perform universal cross-site scripting attacks (UXXS). As a result, a remote attacker can modify a user's Firefox configuration.