Mozilla / Mozilla Firefox User Interface Spoofing Vulnerability
- 0
- Add a Comment
“A vulnerability has been reported in Mozilla and Mozilla Firefox, allowing malicious websites to spoof the user interface. The problem is that Mozilla and Mozilla Firefox don’t restrict websites from including arbitrary, remote XUL (XML User Interface Language) files. This can be exploited to “hijack” most of the user interface (including tool bars, SSL certificate dialogs, address bar and more), thereby controlling almost anything the user sees…. A PoC (Proof of Concept) exploit for Mozilla Firefox has been published. Solution: Do not follow links from untrusted sites.”
