Hello!
I found a vulnerability that allows programs making outgoing internet connections using firefox. I wish that this will be handled in future releases.
Scenario: All outgoing connects are limited to control what is allowed to connect and send data over the internet.
Program X is not allowed to make outgoing calls.
The Vulnerability is, that Program X can start Firefox and send a GET Request containing data by requesting an URL.
It would be great if you would detect who started firefox and put in a whitelist with a dialog to confirm that program X is allowed to start the browser and send requests using the browser.
I found some programs that are already using this vulnerability and I expect that ransomware or malware in general will use this vulnerability as well.
Best regards
miracle152005