Privilege escalation through chrome-loaded about:blank windows
- July 30, 2007
- Firefox, SeaMonkey, Thunderbird
- Fixed in
- Firefox 22.214.171.124
- SeaMonkey 1.1.4
- Thunderbird 126.96.36.199
- Thunderbird 188.8.131.52
Any workaround would depend on the addon in question. One addon known to be affected was the Web Developer Toolbar, which was safe in its default configuration but potentially vulnerable to malicious web content if informational windows were opened as separate windows instead of tabs. The workaround for this, then, is to switch back to the default setting.
Other affected addons might not have a workaround other than to upgrade to a fixed version of Firefox.