1sealsemantic last-mile verification

Research / Finding

Push IPC observer path removed after bug 2022681 report

F-FIREFOX-IPC-PUSH-012

Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.

Read the evidence · View in research browse

Recorded evidence

—score not recorded
mozilla/gecko-devReported fixmozilla/gecko-dev

Push IPC observer path removed after bug 2022681 report

fixed publicly
details
Finding IDs
F-FIREFOX-IPC-PUSH-012
Status
fixed publicly
Reported via
Bugzilla
Note
bug 2022681 remains UNCONFIRMED, but the related fix bug 1862090 was resolved FIXED on 2026-03-13 with status-firefox150 = fixed. the patch removed RecvNotifyPushObservers* and the affected push IPC path. Firefox 150 shipped on 2026-04-21, so this surface is already gone in release.

F-FIREFOX-IPC-PUSH-012: Access control. The removed IPC path concerns principal/scope authorization; removal is not proof of exploitation. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.

Mechanism source for F-FIREFOX-IPC-PUSH-012

Security area (1seal assessment): Authorization. The reported IPC path concerns binding a push scope to its principal. Classifying that boundary does not establish an exploitable cross-origin attack. Reviewed 21 Sep 2026.

Clarify or correct this record privately. The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy.

How this page groups evidence

This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.