Back

CRITICAL KEV

Mozilla: Sandbox escape using Prompt:Open

Published Jul 23, 2019 ·Due Jun 13, 2022

Description

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.

Affected products

Remediation

Red Hat statement

In general, this flaw cannot be exploited through email in Thunderbird because scripting is disabled when reading mail.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Jul 23, 2019
Updated Oct 21, 2025
Reserved May 3, 2019
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jun 20, 2019
ENISA EUVD
Assigner mozilla
Published Jul 23, 2019
Updated Oct 21, 2025
Exploited since May 23, 2022
EUVD-2019-3378