Description
If a document created a sandboxed iframe without allow-scripts, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox.
Solution(s)
mozilla-firefox-upgrade-97_0
Referenceshttps://attackerkb.com/topics/cve-2022-22759 CVE - 2022-22759 http://www.mozilla.org/security/announce/2022/mfsa2022-04.html