When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files. This vulnerability affects Firefox < 74.
Cuando una Web Extension tenía el permiso de todas las direcciones URL y realizaba una petición de extracción con un modo establecido en "same-origin", era posible que la Web Extension lea archivos locales. Esta vulnerabilidad afecta a Firefox versiones anteriores a 74.
Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, spoof the URL or other browser chrome, obtain sensitive information, bypass Content Security Policy protections, or execute arbitrary code. Various other issues were also addressed.