An invalid Polkit Authentication check and missing authentication requirements for D-Bus methods allowed any local user to configure arbitrary VPN se…
When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using an iframe with a source of '…
When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of…
The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function …
A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise return…
By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from expos…
A hyperlink using the res: protocol can be used to open local files at a known location in Internet Explorer if a user approves execution when prompt…
A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Ex…
WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject scripts into contexts where this sh…
The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properl…