Endpoint Vulnerability

XrayWrapper bypass through DOM objects

Description

Mozilla developer Bobby Holley reported that Document Object Model (DOM) objects with some specific properties can bypass XrayWrappers. This can allow web content to confuse privileged code, potentially enabling privilege escalation.

Affected Products

SeaMonkey

References

CVE-2014-8636,