CVE-2019-9812: Critical severity firefox esr vulnerability
Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a malicious Firefox Sync account. Preference settings that disable the sandbox are then synchronized to the local machine and the compromised browser would restart without the sandbox if a crash is triggered.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-9812.
What is the severity of CVE-2019-9812?
The severity of CVE-2019-9812 is high.
How can a sandboxed content process be compromised?
A sandboxed content process can be compromised due to a separate vulnerability.
How can the sandbox be escaped in CVE-2019-9812?
The sandbox can be escaped in CVE-2019-9812 by loading accounts.firefox.com in the compromised process and forcing a log-in to a malicious Firefox Sync account.
Which versions of Mozilla Firefox and Mozilla Firefox ESR are affected by this vulnerability?
Versions up to and including Mozilla Firefox 69 and Mozilla Firefox ESR 68.1 and 60.9 are affected by this vulnerability.