Vulnerability record · CVE-2015-4495 · published 8 August 2015
CVE-2015-4495: Firefox PDF reader same-origin bypass allows file read and privilege gain
Mozilla · Firefox
The PDF reader in Mozilla Firefox (before 39.0.3), Firefox ESR 38.x (before 38.1.1), and Firefox OS (before 2.2) fails to properly validate origin, letting crafted JavaScript combined with a native setter bypass the Same Origin Policy. This matters because it enables reading arbitrary local files and privilege escalation, and Mozilla confirmed it was exploited in the wild in August 2015.
Description
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityConfirmed in-the-wild exploitation, CISA KEV listing, and a high EPSS score with high confidentiality, integrity, and availability impact make this an urgent patch target.
What it is
The PDF reader in Mozilla Firefox (before 39.0.3), Firefox ESR 38.x (before 38.1.1), and Firefox OS (before 2.2) fails to properly validate origin, letting crafted JavaScript combined with a native setter bypass the Same Origin Policy. This matters because it enables reading arbitrary local files and privilege escalation, and Mozilla confirmed it was exploited in the wild in August 2015.
Impact
An attacker can read arbitrary files on the victim's system and gain privileges, breaking the browser's core isolation boundary. This can expose local secrets and enable further compromise of the host.
Attack surface
Reached remotely over the network through crafted JavaScript in a PDF opened in the affected Firefox PDF reader; the CVSS vector (AV:N/PR:N/UI:R) indicates no authentication is needed but user interaction is required to open the malicious content.
Exploitation
Exploitation is confirmed: the description states it was exploited in the wild in August 2015, it is listed in CISA KEV (added 2022-05-25), and an Exploit-DB entry exists; EPSS is 0.71434 (99.4th percentile).
What to do
- Update Firefox to 39.0.3 or later, Firefox ESR to 38.1.1 or later, and Firefox OS to 2.2 or later per Mozilla MFSA 2015-78.
- Apply vendor patches for bundled or derived packages (Red Hat, Ubuntu, SUSE/openSUSE, Oracle Solaris) listed in the advisories.
- Disable or restrict the built-in PDF viewer where feasible until patching is complete.
- Block or sandbox untrusted PDF and JavaScript content delivered through the browser.
- Track CISA KEV remediation due date (2022-06-15) for any remaining unpatched systems.
Detection
- Monitor for Firefox processes reading unexpected local files outside normal profile paths.
- Hunt for PDF files containing JavaScript that invoke native setters or attempt cross-origin access.
- Review proxy and email logs for delivery of PDFs with embedded JavaScript to Firefox users.
- Alert on Firefox versions below 39.0.3 / ESR 38.1.1 present in the environment.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2015-4495 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Mozilla Firefox Security Feature Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.
Affected products
15 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-4495 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-4495), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.