When interacting with an HTML input element's file picker dialog with "webkitdirectory" set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash.
When interacting with an HTML input element's file picker dialog with "webkitdirectory" set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash.
https://www.mozilla.org/security/advisories/mfsa2021-48/ https://bugzilla.mozilla.org/show_bug.cgi?id=1730156