CVE-2019-9816
MEDIUMThunderbird <60.7-Firefox <67-Firefox ESR <60.7 - Code Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-9816. PoCs published by Google Security Research.
AI-analyzed exploit summary This JavaScript PoC exploits a type confusion vulnerability in Mozilla's SpiderMonkey engine by manipulating ObjectGroup assumptions during JIT compilation, leading to a crash in debug builds and potential arbitrary code execution in release builds.
Description
A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.
Exploits (1)
This JavaScript PoC exploits a type confusion vulnerability in Mozilla's SpiderMonkey engine by manipulating ObjectGroup assumptions during JIT compilation, leading to a crash in debug builds and potential arbitrary code execution in release builds.
References (4)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N