Somebody released a PoC for Firefox CVE-2026-8389, and it works.
Uncategorized
1
Posts
1
Posters
0
Views
-
Somebody released a PoC for Firefox CVE-2026-8389, and it works.
The PoC doesn't include a sandbox escape, and claims that
poc-win-sbx.htmlincludes the escape. This file was not shared in the repo.The python server on localhost seems unnecessary, as the exploit web server can surely serve up
primer.jsthe first time thatpayload.jsis requested, and the actualpayload.jsthe second time.
-
R relay@relay.infosec.exchange shared this topic