Cross-origin information leak through web workers

Related Vulnerabilities: CVE-2014-1487  

Mozilla Foundation Security Advisory 2014-09

Cross-origin information leak through web workers

Announced
February 4, 2014
Reporter
Masato Kinugawa
Impact
High
Products
Firefox, Firefox ESR, SeaMonkey, Thunderbird
Fixed in
  • Firefox 27
  • Firefox ESR 24.3
  • SeaMonkey 2.24
  • Thunderbird 24.3

Description

Security researcher Masato Kinugawa reported a cross-origin information leak through web workers' error messages. This violates same-origin policy and the leaked information could potentially be used to gather authentication tokens and other data from third-party websites.

In general this flaw cannot be exploited through email in the Thunderbird and Seamonkey products because scripting is disabled in mail, but is potentially a risk in browser or browser-like contexts.

References