CVE Database
/

CVE-2019-9812

Back to search

CVE-2019-9812

Published: Jan 8, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a malicious Firefox Sync account. Preference settings that disable the sandbox are then synchronized to the local machine and the compromised browser would restart without the sandbox if a crash is triggered. This vulnerability affects Firefox ESR < 60.9, Firefox ESR < 68.1, and Firefox < 69.

VendorProductVersions

Mozilla

Firefox ESR

affected
before 60.9

Mozilla

Firefox ESR

affected
before 68.1

Mozilla

Firefox

affected
before 69

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now