Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with
additional vulnerabilities this could result in executing arbitrary code on the user’s computer.
an exploitable crash.
CVE-2019-11707 Mozilla: BZ – 1721789
CVE-2019-11708 Mozilla: BZ – 1722673