Vulnerability record · CVE-2015-0816 · published 1 April 2015
CVE-2015-0816: Mozilla Firefox and Thunderbird resource: URL Same Origin Policy bypass
Mozilla · Firefox
Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 fail to properly restrict resource: URLs, allowing the Same Origin Policy to be bypassed. This lets remote attackers run arbitrary JavaScript with chrome privileges, as demonstrated via the resource: URL used by PDF.js.
Description
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.
AV:N/AC:L/Au:N/C:N/I:P/A:N
Automated analysis
high priorityThe flaw allows chrome-privilege code execution via a Same Origin Policy bypass, public exploit code exists, and EPSS is very high, though the CVSS impact is limited to integrity.
What it is
Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 fail to properly restrict resource: URLs, allowing the Same Origin Policy to be bypassed. This lets remote attackers run arbitrary JavaScript with chrome privileges, as demonstrated via the resource: URL used by PDF.js.
Impact
An attacker can execute arbitrary JavaScript with chrome (browser-internal) privileges, potentially reading or modifying browser data and escalating beyond normal web content permissions.
Attack surface
Reachable remotely over the network with no authentication required, per the CVSS vector AV:N/AC:L/Au:N. The description does not state whether user interaction such as visiting a crafted page or opening a PDF is required.
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.66936 (99.26th percentile) and a public Exploit-DB entry (37958) exists, indicating known exploit code is available.
What to do
- Upgrade Firefox to 37.0 or later and Firefox ESR to 31.6 or later; upgrade Thunderbird to 31.6 or later.
- Apply vendor and distribution patches (Mozilla MFSA 2015-33, Red Hat, Debian, Ubuntu, SUSE, Gentoo, Oracle) where the browser cannot be upgraded immediately.
- Disable or restrict the PDF.js viewer if it cannot be patched, since the demonstrated vector uses its resource: URL.
- Enforce browser update policies so ESR and Thunderbird installations do not remain on pre-31.6 builds.
Detection
- Monitor for resource: URL usage in browser or Thunderbird process activity, especially in conjunction with PDF.js.
- Alert on unexpected JavaScript execution or chrome-privilege errors logged by Firefox or Thunderbird.
- Track endpoint versions of Firefox, Firefox ESR and Thunderbird and flag any below 37.0 / 31.6.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-0816 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-0816), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.