Prototype Pollution Vulnerability in Firefox ESR and Thunderbird by Mozilla
CVE-2022-1529
8.8HIGH
Key Information:
- Vendor
Mozilla
- Vendor
- CVE Published:
- 22 December 2022
What is CVE-2022-1529?
A vulnerability exists in Mozilla's Firefox ESR, Firefox for Android, and Thunderbird products that allows an attacker to send specially crafted messages to the parent process. This can lead to double-indexing within a JavaScript object, resulting in prototype pollution. Consequently, this may enable attackers to execute arbitrary JavaScript code in the context of the privileged parent process, posing significant security risks to users.
Affected Version(s)
Firefox < 100.0.2
Firefox ESR < 91.9.1
Firefox for Android < 100.3.0