SHARE
Facebook X Pinterest WhatsApp

Chicken? Or the Egg?

Written By
thumbnail
Web Webster
Web Webster
Jul 13, 2007

There’s this debate right now going on about a security hole in Firefox.

I haven’t linked to any of the coverage on Linux Today, because it seems to be a Windows-only issue. Interestingly, this exploit seems to also depend on Internet Explorer, and right now security analysts can’t seem to decide which browser is more at fault.

Here’s what’s happening.

If an IE user clicks on a firefoxurl: URI, the new page is launched in Firefox. According to Steve Kerrison over at Hexus:

Thor Larholm, discoverer of the flaw, writes: “it is possible to specify arbitrary arguments to the ‘firefox.exe’ process. This is where the ‘-chrome’ command line argument comes in handy, as it allows us to specify arbitrary Javascript code which is then executed within the privileges of trusted Chrome content…”

The debate comes in with these two sides of the argument: IE lets the fake request through, but Firefox still accepts it. Which, then, is more at fault?

Well, seeing how this fault isn’t showing up on Linux, or OS X for that matter, the fault clearly lies with…

Windows, perhaps the biggest exploit of them all.

thumbnail
Web Webster

Web Webster

Web Webster has more than 20 years of writing and editorial experience in the tech sector. He’s written and edited news, demand generation, user-focused, and thought leadership content for business software solutions, consumer tech, and Linux Today, he edits and writes for a portfolio of tech industry news and analysis websites including webopedia.com, and DatabaseJournal.com.

Recommended for you...

LXQt 2.3 Desktop Environment Released with Better Wayland Support
Bobby Borisov
Nov 17, 2025
Flatpak Development Restarts with Fresh Energy and Clear Direction
Bobby Borisov
Nov 17, 2025
TEAMGROUP ULTRA Micro SDXC A2 V30 Memory Card 1TB Review
webmaster
Nov 17, 2025
Steam Deck Adds Display-Off Mode for Low-Power Downloads
Bobby Borisov
Nov 17, 2025
Linux Today Logo

LinuxToday is a trusted, contributor-driven news resource supporting all types of Linux users. Our thriving international community engages with us through social media and frequent content contributions aimed at solving problems ranging from personal computing to enterprise-level IT operations. LinuxToday serves as a home for a community that struggles to find comparable information elsewhere on the web.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.