[arch-security] [ASA-201602-12] firefox: same-origin policy bypass