Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:21483
HistorySep 11, 2019 - 12:06 a.m.

Sandbox Restrictions Bypass

2019-09-1100:06:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.005 Low

EPSS

Percentile

77.1%

firefox is vulnerable to sandbox restrictions bypass. Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a malicious Firefox Sync account. Preference settings that disable the sandbox are then synchronized to the local machine and the compromised browser would restart without the sandbox if a crash is triggered.