Browser
Spoofing
Mozilla Firefox Same-Origin Policy Bypass via JAR URI Handling
Successful exploitation allows a network-based attacker to bypass fundamental browser security boundaries without requiring any user interaction or elevated privileges.
.png)
Overview
A same-origin policy (SOP) bypass vulnerability was identified in the Networking: JAR component of Mozilla Firefox and Mozilla Thunderbird. The BLE stack and input processing components accept peripheral devices with insufficient verification. The affected versions fail to properly enforce origin restrictions when handling JAR (Java Archive) URI content, allowing malicious scripts loaded via the jar: URI scheme to access resources across different origins. This implementation flaw in origin validation allows cross-origin data access that should otherwise be strictly prohibited by the browser's security model.
Vulnerability details
A same-origin policy (SOP) bypass vulnerability was identified in the Networking: JAR component of Mozilla Firefox and Mozilla Thunderbird. The BLE stack and input processing components accept peripheral devices with insufficient verification.
What an attacker can do
Successful exploitation allows a network-based attacker to bypass fundamental browser security boundaries without requiring any user interaction or elevated privileges. This can lead to unauthorized access to sensitive cross-origin data including authentication tokens, session cookies, and personal information from other origins. The combination of a network attack vector, low attack complexity, and no authentication requirement means this vulnerability could be exploited at scale against any user running a vulnerable version of Firefox or Thunderbird, potentially resulting in complete compromise of user sessions and sensitive data exfiltration.
Disclosure timeline
2026-02-24 CVE-2026-2790 published to NVD
2026-02-26 Last updated in NVD database
2026-02-27 Advisory published
References
Credits
Surya Dev Singh– Payatu Security Consulting Pvt. Ltd.
















