EXPOSURES › CVE-2015-4495
CVE-2015-4495
HIGH ⌖ ON CISA KEV · EXPLOITEDFirefox bypassed Same Origin Policy allowing remote attackers to read arbitrary files or gain privileges.
This vulnerability allowed remote attackers to bypass Firefox's Same Origin Policy, enabling arbitrary file reads and privilege escalation. DIB organizations must ensure their browsers are patched, as this flaw was actively exploited in the wild and could compromise sensitive data or system integrity. The failure stems from an unpatched security bypass that was exploited before a patch existed, highlighting the risk of relying on outdated software.
Shame score — The vulnerability was actively exploited in the wild and allowed remote attackers to bypass critical security controls, indicating a significant avoidable risk due to unpatched software.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges.