WebExtensions bundled with embedded experiments were not correctly checked for proper authorization before Firefox 61.0. This allowed a malicious WebExtension to gain full browser permissions.
WebExtensions bundled with embedded experiments were not correctly checked for proper authorization before Firefox 61.0. This allowed a malicious WebExtension to gain full browser permissions.
https://www.mozilla.org/en-US/security/advisories/mfsa2018-15/#CVE-2018-12369 https://bugzilla.mozilla.org/show_bug.cgi?id=1454909