Medium firefox Logic Error

Overview

Medium
Severity
CVSS
No
Exploited ITW
Embargoed
Fix Status
Impactmoderate
DescriptionEnhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content.
ComponentCore
Bug ClassLogic Error
Tracker1924167
CISA KEVNot listed
CreditedMasato Kinugawa
Disclosed2024-11-26

Fix not yet public

No public source fix for this bug has been identified on the main branch yet — it is embargoed or not yet disclosed. Root-cause analysis is withheld until the fix commit is available.
On This Page