Related Vulnerabilities: CVE-2022-29909  

A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes the issue of documents in deeply-nested cross-origin browsing contexts that could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions.

Description

A flaw was found in Mozilla. The Mozilla Foundation Security Advisory describes the issue of documents in deeply-nested cross-origin browsing contexts that could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions.

Additional Information

  • Bugzilla 2081469: CVE-2022-29909 Mozilla: Bypassing permission prompt in nested browsing contexts
  • CWE-281: Improper Preservation of Permissions
  • FAQ: Frequently asked questions about CVE-2022-29909