1. Symantec/
  2. Security Response/
  3. Attack Signatures/
  4. Web Attack: Mozilla Firefox CVE-2015-4495 2

Web Attack: Mozilla Firefox CVE-2015-4495 2

Severity: High

This attack could pose a serious security threat. You should take immediate action to stop any damage or prevent further damage from happening.

Description

This would allow an attacker to read and steal sensitive local files on the victim's computer.

Additional Information

Security researcher Cody Crews reported on a way to violate the same origin policy and inject script into a non-privileged part of the built-in PDF Viewer. This would allow an attacker to read and steal sensitive local files on the victim's computer.

Mozilla has received reports that an exploit based on this vulnerability has been found in the wild.

Affected

  • Firefox, Firefox ESR, Firefox OS
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube