Vulnerability record · CVE-2014-8636 · published 14 January 2015
CVE-2014-8636: Firefox XrayWrapper DOM named getter flaw allows privileged JavaScript injection
Mozilla · Firefox
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 fails to properly interact with a DOM object that has a named getter. This can let remote attackers execute arbitrary JavaScript with chrome (browser-internal) privileges. Because chrome-level code runs outside the normal web sandbox, the flaw undermines the browser's core security boundary.
Description
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with a DOM object that has a named getter, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via unspecified vectors.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw allows remote, unauthenticated chrome-privilege code execution and has high EPSS with public exploit tooling, though it is not in KEV and affects only older browser versions.
What it is
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 fails to properly interact with a DOM object that has a named getter. This can let remote attackers execute arbitrary JavaScript with chrome (browser-internal) privileges. Because chrome-level code runs outside the normal web sandbox, the flaw undermines the browser's core security boundary.
Impact
An attacker who triggers the flaw gains arbitrary JavaScript execution at chrome privileges, which can lead to full compromise of the browser process and the user's system. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.
Attack surface
The CVSS 2.0 vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication required. The description does not state whether user interaction (such as visiting a crafted page) is needed, so that detail is absent from the record.
Exploitation
CVE-2014-8636 is not listed in CISA KEV, but EPSS is high at 0.6476 (99.2nd percentile). References include a Rapid7 Metasploit disclosure and a Packet Storm posting, indicating public exploit tooling exists, though the record does not confirm in-the-wild use.
What to do
- Upgrade Firefox to 35.0 or later and SeaMonkey to 2.32 or later; these are the fixed versions named in the advisory.
- Apply the vendor and Linux distribution updates referenced in the Mozilla MFSA 2015-09 and openSUSE/Gentoo advisories.
- If immediate upgrade is not possible, restrict browsing to trusted sites and consider disabling or sandboxing the affected browser.
- Track the Mozilla bug 987794 and vendor advisory for any backported fixes on long-term support branches.
Detection
- Monitor for Firefox or SeaMonkey versions below 35.0 / 2.32 in endpoint and vulnerability inventory.
- Hunt for browser processes spawning unexpected child processes or writing outside normal profile paths, which can indicate chrome-privilege code execution.
- Review proxy or network logs for known exploit delivery patterns tied to the Rapid7 Metasploit module and Packet Storm disclosure.
- Correlate endpoint telemetry for anomalous JavaScript engine activity or crashes in the XrayWrapper code path.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-8636 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-8636), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.