CVE-2019-9812
Published: Jan 8, 2020
Modified: Aug 4, 2024
Description
Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a malicious Firefox Sync account. Preference settings that disable the sandbox are then synchronized to the local machine and the compromised browser would restart without the sandbox if a crash is triggered. This vulnerability affects Firefox ESR < 60.9, Firefox ESR < 68.1, and Firefox < 69.
| Vendor | Product | Versions |
|---|---|---|
Mozilla | Firefox ESR | affected before 60.9 |
Mozilla | Firefox ESR | affected before 68.1 |
Mozilla | Firefox | affected before 69 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now