Executive brief
A security vulnerability in the Firefox web browser could allow a malicious website to bypass the Same-Origin Policy, which is a fundamental security boundary. This could enable an attacker to access sensitive data from other websites you have open or perform actions on your behalf without authorization. Users should update to Firefox 151 or later to protect their browsing sessions.
Technical details
A Same-Origin Policy (SOP) bypass exists within the DOM: Networking component of Mozilla Firefox. The vulnerability allows a malicious origin to circumvent standard browser security boundaries to interact with or extract data from a different origin. While specific root cause details are restricted in the associated bug report (Bug 2038803), SOP bypasses typically involve flaws in how the browser handles cross-origin requests or document access within the networking stack. An attacker could exploit this by enticing a user to visit a specially crafted webpage, potentially leading to the theft of session cookies, sensitive user data, or unauthorized API interactions. The issue is fixed in Firefox 151.
Affected products
- Mozilla Firefox < 151
Timeline
- 2026-05-19: advisory: Mozilla Foundation Security Advisory 2026-46 released
- 2026-05-19: patched: Fixed in Firefox 151