Browser

Spoofing

Mozilla Firefox Same-Origin Policy Bypass via JAR URI Handling

Successful exploitation allows a network-based attacker to bypass fundamental browser security boundaries without requiring any user interaction or elevated privileges.

8.8
/ 10
High
CVSS v3.1
ADVISORY ID
PS97
PUBLISHED
2026-03-17
CVE IDs
CVE-2026-2790
VENDORS
Mozilla
PUBLIC EXPLOIT
None indexed
CWE
CWE-346
PRODUCT
Firefox / Thunderbird
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

A same-origin policy (SOP) bypass vulnerability was identified in the Networking: JAR component of Mozilla Firefox and Mozilla Thunderbird. The BLE stack and input processing components accept peripheral devices with insufficient verification. The affected versions fail to properly enforce origin restrictions when handling JAR (Java Archive) URI content, allowing malicious scripts loaded via the jar: URI scheme to access resources across different origins. This implementation flaw in origin validation allows cross-origin data access that should otherwise be strictly prohibited by the browser's security model.

Vulnerability details

Vulnerability details

CVE-2026-2790
CWE-346
High | 8.8

A same-origin policy (SOP) bypass vulnerability was identified in the Networking: JAR component of Mozilla Firefox and Mozilla Thunderbird. The BLE stack and input processing components accept peripheral devices with insufficient verification.

Auth:
None (remote, user interaction required)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
Impact

What an attacker can do

Successful exploitation allows a network-based attacker to bypass fundamental browser security boundaries without requiring any user interaction or elevated privileges. This can lead to unauthorized access to sensitive cross-origin data including authentication tokens, session cookies, and personal information from other origins. The combination of a network attack vector, low attack complexity, and no authentication requirement means this vulnerability could be exploited at scale against any user running a vulnerable version of Firefox or Thunderbird, potentially resulting in complete compromise of user sessions and sensitive data exfiltration.

DISCLOSURE

Disclosure timeline

2026-02-24 CVE-2026-2790 published to NVD

2026-02-26 Last updated in NVD database

2026-02-27 Advisory published

Credits

Surya Dev Singh– Payatu Security Consulting Pvt. Ltd.