<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Somebody released a PoC for Firefox CVE-2026-8389, and it works.]]></title><description><![CDATA[<p>Somebody released a <a href="https://github.com/crixpwn/CVE-2026-8389" rel="nofollow noopener">PoC for Firefox CVE-2026-8389</a>, and it works.</p><p>The PoC doesn't include a sandbox escape, and claims that <code>poc-win-sbx.html</code> includes the escape.  This file was not shared in the repo.</p><p>The python server on localhost seems unnecessary, as the exploit web server can surely serve up <code>primer.js</code> the first time that <code>payload.js</code> is requested, and the actual <code>payload.js</code> the second time.  <img src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f914.png?v=28325c671da" class="not-responsive emoji emoji-android emoji--thinking_face" style="height:23px;width:auto;vertical-align:middle" title="🤔" alt="🤔" /></p>]]></description><link>https://board.circlewithadot.net/topic/2aa0db10-4688-4e62-8315-79ce274aece7/somebody-released-a-poc-for-firefox-cve-2026-8389-and-it-works.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 05 Jun 2026 17:37:24 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/2aa0db10-4688-4e62-8315-79ce274aece7.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 05 Jun 2026 12:59:47 GMT</pubDate><ttl>60</ttl></channel></rss>