MLS IPC principal validation hardening
details
- Finding IDs
- F-FIREFOX-IPC-MLS-009
- Status
- released
- Recorded credit
- Mozilla Bug 2020535 lists Oleh Konko (1seal) as reporter. Patch author: Benjamin Beurdouche; review: nika. Reporter credit does not imply patch authorship.
- Note
- Mozilla records RESOLVED FIXED and firefox152 fixed (Firefox 152). Classified sec-other and unsupported-config; this is a hardening result, not a confirmed HIGH-severity vulnerability or a new CVE. The original harness ran in the same process and does not establish the broader scenario between independent processes. Private attachments are not republished.
F-FIREFOX-IPC-MLS-009: Verification failures. MLS IPC checks whether the submitted principal could be loaded by the sending process remote type; this is the public hardening scope, not proof of independent cross-process exploitation. Reviewed 7 Oct 2026. Mechanism assessed by 1seal.
Mechanism source for F-FIREFOX-IPC-MLS-009
Security area (1seal assessment): Identity. The public patch validates the incoming MLS principal against the sending content process remote type. Mozilla classifies the report as sec-other and unsupported-config. Reviewed 7 Oct 2026.