Junglewise Threat Intelligence

CVE-2015-4495: Mozilla Firefox Security Feature Bypass Vulnerability

CVE-2015-4495 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-05-25

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

The PDF reader in Mozilla Firefox allows remote attackers to bypass the Same Origin Policy (SOP) via crafted JavaScript code and a native setter. This vulnerability enables attackers to read arbitrary local files or gain elevated privileges, and was notably exploited in the wild to target sensitive user data.

Affected products

  • Mozilla Firefox before 39.0.3
  • Mozilla Firefox ESR 38.x before 38.1.1
  • Mozilla Firefox OS before 2.2

Timeline

  • 2015-08-06: disclosed: Exploit found in the wild reported by Mozilla blog
  • 2015-08-01: exploited: Exploited in the wild in August 2015
  • 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats