FireFox Check If Local File/Folder Exists Using Jar URI Scheme
This bug only works on local HTML files (in other words using File:// URI scheme)
There was an update on FireFox disabling JAR files remotely, but this is not the case for local documents. You can still open and reference a JAR file iff you do it from a local file, which gave me some time to test it.
This was a pretty simple bug but with some potential for harm, you essentially could check if certain files or folders existed anywhere in the victims local disk, but you could not read them.
I think the original PoC speaks for itself.
Original PoC code:
Within an HTML file: that contains an iframe with the id 'qab'
We can safely infer that the folder 'does-not-exist' doesn't and 'Temp' does. We can do the same with files.
The Bugzilla report: https://bugzilla.mozilla.org/show_bug.cgi?id=1247968
jar protocol support has been disabled by default: https://www.fxsitecompat.com/en-CA/docs/2015/jar-protocol-support-has-been-disabled-by-default/