CVE-2016-2817 — Firefox vulnerability
Severity
5.4MEDIUMNVD
OSV8.8
EPSS
0.4%
top 39.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 30
Latest updateMay 17
Description
The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.5
Affected Packages4 packages
🔴Vulnerability Details
4📋Vendor Advisories
5💬Community
1Bugzilla▶
CVE-2016-2817 Mozilla: Elevation of privilege with chrome.tabs.update API in web extensions (MFSA 2016-46)↗2016-04-25