Browser

Spoofing

CVE-2026-8971: Mozilla Firefox Same-Origin Policy Bypass via JAR URI Null Byte Handling

Exploitation occurs when a target loads a specifically crafted jar:, resource:///, or moz-extension:// URI, whether through direct navigation, a redirect served by attacker controlled web content, or…

8.8
/ 10
High
CVSS v3.1
ADVISORY ID
PS103
PUBLISHED
2026-06-17
CVE IDs
CVE-2026-8971, CVE-2025-1936, CVE-2026-2790
VENDORS
Mozilla
PUBLIC EXPLOIT
None indexed
CWE
CWE-158, CWE-346
PRODUCT
Firefox
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

A same origin policy bypass vulnerability was identified in the Networking: JAR component of Mozilla Firefox. The affected versions fail to reject a null byte (%00) embedded in a jar: or resource:/// URI path before that value reaches downstream filename resolution and content type derivation logic. Because origin and content type attribution for jar: backed resources depend on correctly resolving the inner archive entry name, an unrejected null byte allows the browser to associate one resource's declared identity with content actually served under a different identity.

This is exploitable through two related primitives. First, a crafted jar:file:/// URI can force Firefox to present a completely attacker chosen download filename and extension regardless of the archive's real contents. Second, a null byte placed before a file extension causes Firefox to derive the MIME type from the attacker supplied suffix rather than the actual resource, producing a content type mismatch. Because resource:/// resolves internally to jar:, and moz-extension:// resolves internally to resource:///, the same defect is reachable through any installed browser extension that declares a wildcard entry in web_accessible_resources, extending the practical attack surface from local file URIs to ordinary web content.

This is the third vulnerability in the same root cause chain. CVE-2025-1936 first identified null byte handling issues in JAR entry resolution and was fixed by replacing unsafe C string handling with a length aware string type. CVE-2026-2790 found that a double encoded null byte (%2500) bypassed that fix and was patched by disabling content sniffing for JAR channels entirely. CVE-2026-8971 demonstrates that neither prior fix rejected the null byte at the URL parsing layer itself, leaving the filename resolution and MIME type derivation logic, two further downstream consumers of the same unsanitized value, still exploitable.

Vulnerability details

Vulnerability details

CVE-2026-8971
CWE-346
Medium | 6.5

A same origin policy bypass vulnerability was identified in the Networking: JAR component of Mozilla Firefox.

Auth:
None (remote)
Impact:
Limited data disclosure, limited data tampering
CVE-2025-1936
CWE-158
High | 7.3

First flaw in the same chain: null byte handling in JAR entry resolution, fixed by replacing unsafe C string handling with a length aware string type.

Auth:
None (remote)
Impact:
Limited data disclosure, limited data tampering, partial service degradation
CVE-2026-2790
CWE-346
High | 8.8

Second flaw in the chain: a double encoded null byte (%2500) bypassed the earlier fix. Patched by disabling content sniffing for JAR channels.

Auth:
None (remote, user interaction required)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
Impact

What an attacker can do

Exploitation occurs when a target loads a specifically crafted jar:, resource:///, or moz-extension:// URI, whether through direct navigation, a redirect served by attacker controlled web content, or a link embedded in another document. It does not allow remote code execution on its own. The realistic impact is a same origin attribution failure that enables filename and content type spoofing: an attacker can cause Firefox to offer a download under a fully attacker controlled filename and extension while the underlying content is something else, or cause a resource to be served and rendered under an incorrect MIME type. Where the vulnerable path is reached through an installed extension's web_accessible_resources surface, the spoofed response still appears to originate from that extension's legitimate origin, which can be used to make a malicious download appear trustworthy or to slip mislabeled content past automated extension review tooling that inspects files by extension.

DISCLOSURE

Disclosure timeline

2026-04-16 Reported to Mozilla via Bugzilla (Bug 2032604)

2026-04-21 Patch landed on mozilla-central

2026-04-22 Bounty awarded; publication approved

2026-05-19 CVE-2026-8971 published via MFSA2026-46, fixed in Firefox 151

Credits

Surya Dev Singh – Payatu Security Consulting Pvt. Ltd.