Thursday, August 02, 2007

Mozilla released Firefox 2.0.0.6

The first is a vulnerability caused by an error in the handling of "about:blank" pages loaded by chrome in an addon. This can be exploited to execute script code under chrome privileges by e.g.
clicking on a link opened in an "about:blank" window created and populated in a certain ways by an addon.