Hacker News new | ask | show | jobs
by revelation 3870 days ago
Except they, naturally, found that all this sandboxing was a tad too restrictive, and ended up adding Apple-esque exceptions for their own code.

And in doing so, a critical vulnerability:

https://www.mozilla.org/en-US/security/advisories/mfsa2015-7...

1 comments

They are not "Apple-esque exceptions for their own code". All JS code running as browser extensions have those permissions.