‼️🚨 Security researcher ggwhyp demonstrated a full-chain Firefox exploit on Windows.
He opens an HTML page, Firefox runs the code, cmd.exe spawns, Calculator opens. Signature of a browser-to-OS exploit.
Prepared for Pwn2Own. ZDI rejected it. According to the researcher, it was responsibly disclosed to Mozilla.