Executive brief
The PDF reader in Mozilla Firefox allows remote attackers to bypass the Same Origin Policy (SOP) via crafted JavaScript code and a native setter. This vulnerability enables attackers to read arbitrary local files or gain elevated privileges, and was notably exploited in the wild to target sensitive user data.
Affected products
- Mozilla Firefox before 39.0.3
- Mozilla Firefox ESR 38.x before 38.1.1
- Mozilla Firefox OS before 2.2
Timeline
- 2015-08-06: disclosed: Exploit found in the wild reported by Mozilla blog
- 2015-08-01: exploited: Exploited in the wild in August 2015
- 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog