You are here: Security Center > Mozilla Foundation Security Advisories > MFSA 2012-95

Mozilla Foundation Security Advisory 2012-95

Title: Javascript: URLs run in privileged context on New Tab page
Impact: Moderate
Announced: November 20, 2012
Reporter: kakzz.ng@gmail.com
Products: Firefox

Fixed in: Firefox 17.0

Description

Security researcher kakzz.ng@gmail.com reported that if a javascript: URL is selected from the list of Firefox "new tab" page, the script will inherit the privileges of the privileged "new tab" page. This allows for the execution of locally installed programs if a user can be convinced to save a bookmark of a malicious javascript: URL.

References