Executive brief
A security flaw in the Firefox web browser could allow a malicious website to bypass standard security boundaries. This could potentially allow an attacker to access data from other websites that the user has open, compromising the privacy of their browsing session. Users should update to Firefox 151 or later to resolve this issue.
Technical details
A same-origin policy (SOP) bypass vulnerability was identified in the Networking: JAR component of Mozilla Firefox. The flaw resides in how the browser handles JAR (Java Archive) files within its networking stack, potentially allowing a malicious site to access resources from a different origin. An attacker could exploit this by enticing a user to visit a specially crafted webpage, leading to unauthorized information disclosure. The vulnerability is fixed in Firefox 151. Mozilla has classified this specific issue with a 'low' impact rating.
Affected products
- Mozilla Firefox < 151
Timeline
- 2026-05-19: advisory: Mozilla Foundation Security Advisory 2026-46 published
- 2026-05-19: patched: Fixed in Firefox 151