A vulnerability in how Firefox handles chrome: addresses, which are used to load specific Firefox and extensions’ interface elements like windows, buttons and dialogs, could allow a malicious site to access local files in known locations. The vulnerability affects extensions that are installed as a set of uncompressed files, as opposed to the more common
http://feedproxy.google.com/~r/MozillaLinks/~3/6gE8PXK1o0o/