PT-2022-15656 · Mozilla+1 · Firefox+1

Jed Davis

·

Published

2022-01-11

·

Updated

2024-12-12

·

CVE-2022-22750

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 96
Description A compromised content process could confuse higher privileged processes into interacting with resource handles that the unprivileged process should not have access to, by generally accepting and passing resource handles across processes. This issue only affects Firefox for Windows and MacOS, with other operating systems being unaffected.
Recommendations For Firefox versions prior to 96, update to version 96 or later to resolve the issue. As a temporary workaround, consider restricting interactions between processes to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2022-1053
ALT-PU-2022-2930
ALT-PU-2023-1139
ALT-PU-2023-4336
ALT-PU-2023-4339
CVE-2022-22750
OPENSUSE-SU-2024:11732-1
OPENSUSE-SU-2024:14572-1

Affected Products

Alt Linux
Firefox