Back

MEDIUM

Mozilla: Extensions granted downloads.open permission could open arbitrary applications on Mac OSX

Published Mar 2, 2020

Description

By downloading a file with the .fileloc extension, a semi-privileged extension could launch an arbitrary application on the user's computer. The attacker is restricted as they are unable to download non-quarantined files or supply command line arguments to the application, limiting the impact. Note: this issue only occurs on Mac OSX. Other operating systems are unaffected. This vulnerability affects Thunderbird < 68.5, Firefox < 73, and Firefox < ESR68.5.

Affected products

Remediation

No remediation recorded yet.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Mar 2, 2020
Updated Aug 4, 2024
Reserved Jan 10, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Feb 11, 2020
ENISA EUVD
Assigner mozilla
Published Mar 2, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-27944