Browser
Spoofing
CVE-2026-8971: Mozilla Firefox Same-Origin Policy Bypass via JAR URI Null Byte Handling
Exploitation occurs when a target loads a specifically crafted jar:, resource:///, or moz-extension:// URI, whether through direct navigation, a redirect served by attacker controlled web content, or…
.png)
Overview
A same origin policy bypass vulnerability was identified in the Networking: JAR component of Mozilla Firefox. The affected versions fail to reject a null byte (%00) embedded in a jar: or resource:/// URI path before that value reaches downstream filename resolution and content type derivation logic. Because origin and content type attribution for jar: backed resources depend on correctly resolving the inner archive entry name, an unrejected null byte allows the browser to associate one resource's declared identity with content actually served under a different identity.
This is exploitable through two related primitives. First, a crafted jar:file:/// URI can force Firefox to present a completely attacker chosen download filename and extension regardless of the archive's real contents. Second, a null byte placed before a file extension causes Firefox to derive the MIME type from the attacker supplied suffix rather than the actual resource, producing a content type mismatch. Because resource:/// resolves internally to jar:, and moz-extension:// resolves internally to resource:///, the same defect is reachable through any installed browser extension that declares a wildcard entry in web_accessible_resources, extending the practical attack surface from local file URIs to ordinary web content.
This is the third vulnerability in the same root cause chain. CVE-2025-1936 first identified null byte handling issues in JAR entry resolution and was fixed by replacing unsafe C string handling with a length aware string type. CVE-2026-2790 found that a double encoded null byte (%2500) bypassed that fix and was patched by disabling content sniffing for JAR channels entirely. CVE-2026-8971 demonstrates that neither prior fix rejected the null byte at the URL parsing layer itself, leaving the filename resolution and MIME type derivation logic, two further downstream consumers of the same unsanitized value, still exploitable.
Vulnerability details
A same origin policy bypass vulnerability was identified in the Networking: JAR component of Mozilla Firefox.
First flaw in the same chain: null byte handling in JAR entry resolution, fixed by replacing unsafe C string handling with a length aware string type.
Second flaw in the chain: a double encoded null byte (%2500) bypassed the earlier fix. Patched by disabling content sniffing for JAR channels.
What an attacker can do
Exploitation occurs when a target loads a specifically crafted jar:, resource:///, or moz-extension:// URI, whether through direct navigation, a redirect served by attacker controlled web content, or a link embedded in another document. It does not allow remote code execution on its own. The realistic impact is a same origin attribution failure that enables filename and content type spoofing: an attacker can cause Firefox to offer a download under a fully attacker controlled filename and extension while the underlying content is something else, or cause a resource to be served and rendered under an incorrect MIME type. Where the vulnerable path is reached through an installed extension's web_accessible_resources surface, the spoofed response still appears to originate from that extension's legitimate origin, which can be used to make a malicious download appear trustworthy or to slip mislabeled content past automated extension review tooling that inspects files by extension.
Disclosure timeline
2026-04-16 Reported to Mozilla via Bugzilla (Bug 2032604)
2026-04-21 Patch landed on mozilla-central
2026-04-22 Bounty awarded; publication approved
2026-05-19 CVE-2026-8971 published via MFSA2026-46, fixed in Firefox 151
References
Credits
Surya Dev Singh – Payatu Security Consulting Pvt. Ltd.
















