Back

CRITICAL

Mozilla: Sandbox escape through Firefox Sync

Published Jan 8, 2020

Description

Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a malicious Firefox Sync account. Preference settings that disable the sandbox are then synchronized to the local machine and the compromised browser would restart without the sandbox if a crash is triggered. This vulnerability affects Firefox ESR < 60.9, Firefox ESR < 68.1, and Firefox < 69.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Jan 8, 2020
Updated Aug 4, 2024
Reserved Mar 14, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 3, 2019