#VU60397 Improper control of a resource through its lifetime in Mozilla Firefox - CVE-2022-22755
Published: February 8, 2022
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to the way XSL documents are handled by the browser. A remote attacker can trick the victim to load a specially crafted XSL document that can continue JavaScript execution within the bounds of the same-origin policy even after the browser tab is closed.