Privilege escalation through chrome-loaded about:blank windows
- July 30, 2007
- Firefox, SeaMonkey, Thunderbird
- Fixed in
- Firefox 18.104.22.168
- SeaMonkey 1.1.4
- Thunderbird 22.214.171.124
- Thunderbird 126.96.36.199
Any workaround would depend on the addon in question. One addon known to be affected was the Web Developer Toolbar, which was safe in its default configuration but potentially vulnerable to malicious web content if informational windows were opened as separate windows instead of tabs. The workaround for this, then, is to switch back to the default setting.
Other affected addons might not have a workaround other than to upgrade to a fixed version of Firefox.