firefox-152.0.5-backup-nss-rce-poc: Targeting Firefox’s NSS Module Loader for RCE

The firefox-152.0.5-backup-nss-rce-poc exploit targets Firefox’s NSS (Network Security Services) PKCS#11 module-loading mechanism, specifically abusing the dynamic library loading path triggered during profile backup restoration to achieve remote code execution.

The firefox-152.0.5-backup-nss-rce-poc proof-of-concept in the bikini/exploitarium repository demonstrates how attackers can weaponize Firefox’s legitimate backup-restore workflow. By delivering a crafted profile archive containing a malicious module definition, the exploit forces NSS to load an attacker-controlled DLL when Firefox restarts, bypassing typical security boundaries through trusted infrastructure.

How the firefox-152.0.5-backup-nss-rce-poc Exploit Works

The NSS Module Loading Mechanism

Firefox relies on the NSS (Network Security Services) library for cryptographic operations and security token management. During initialization, NSS parses the pkcs11.txt configuration file to discover and load PKCS#11 modules specified by the user or enterprise policy. According to the source analysis in README.md (lines 7-15), the vulnerability exists because Firefox’s backup restoration process automatically merges NSS configuration files without validating the library= paths contained within them.

Profile Backup Manipulation

The exploit leverages Firefox’s profile backup format, which stores user data including NSS configuration files in an unencrypted archive. The build_backup.py script generates a malicious backup containing a crafted pkcs11.txt entry that points to a Windows DLL payload. When Firefox restores this backup, it writes the attacker-controlled configuration to the profile directory, preserving the malicious library path.

Dynamic Library Execution

Upon restart, the Firefox parent process initializes NSS, which calls PR_LoadLibraryWithFlags on the attacker-supplied path (as referenced in utilmod.c lines 39-40). This causes Windows to load firefox_calc_payload.dll into the privileged parent process. The DLL’s DllMain entry point immediately executes WinExec("calc.exe"), demonstrating arbitrary code execution with the privileges of the Firefox process.

Key Components in the bikini/exploitarium Repository

The exploit chain consists of several coordinated components:

  • build_backup.py — Generates the malicious Firefox profile backup containing the poisoned pkcs11.txt configuration
  • server.py — Hosts the payload DLL and backup archive, resolving the Windows Downloads folder to ensure reliable delivery
  • exploit.html — Client-side delivery mechanism that triggers downloads and dispatches privileged BrowserBridge actions using Wasm-based primitives
  • firefox_calc_payload.dll — The malicious Windows DLL executed by NSS during module loading
  • calc_payload.c — Source code demonstrating the WinExec("calc.exe") invocation in the DLL entry point
  • native_browserbridge.wasm — WebAssembly module providing the Baseline-JIT memory-safety primitive used to gain native control

Reproduction Workflow

The following steps reproduce the exploitation chain on Windows 11 x64 with Firefox 152.0.5. Run this only in authorized testing environments:


# 1. Install Python dependencies (>=3.8 required)

python -m pip install -r requirements.txt

# 2. Start the local HTTP server to serve exploit assets

python -B server.py

# Output: http://127.0.0.1:8896/

# 3. Navigate to the server URL in the target Firefox binary

"C:\Path\To\firefox.exe" "http://127.0.0.1:8896/"

# 4. Automatic exploitation sequence:

#    • Downloads payload DLL and crafted backup to %USERPROFILE%\Downloads

#    • Firefox restores the backup, merging the malicious pkcs11.txt

#    • NSS loads firefox_calc_payload.dll via PR_LoadLibraryWithFlags

#    • calc.exe spawns, confirming RCE

Security Notice: This PoC is intended strictly for defensive research, regression testing, and hardening Firefox’s backup/NSS code paths. Do not deploy against systems without explicit authorization.

Summary

  • The firefox-152.0.5-backup-nss-rce-poc targets Firefox’s NSS PKCS#11 module loader, specifically the PR_LoadLibraryWithFlags code path invoked during profile initialization.
  • Attackers achieve RCE by injecting a malicious library= path into pkcs11.txt through the backup restoration workflow.
  • The exploit requires Firefox to process a crafted backup archive containing an attacker-controlled DLL reference.
  • Execution occurs in the Firefox parent process when NSS initializes and loads the specified module, granting the payload elevated privileges compared to sandboxed content processes.

Frequently Asked Questions

What specific Firefox component does firefox-152.0.5-backup-nss-rce-poc target?

The exploit targets NSS (Network Security Services), specifically the PKCS#11 module loading mechanism that parses pkcs11.txt and calls PR_LoadLibraryWithFlags to load cryptographic provider DLLs. The vulnerability exists in how Firefox’s backup restoration logic trusts NSS configuration files without sanitizing library paths.

How does the malicious payload execute after the backup restores?

When Firefox restarts after restoring the malicious backup, NSS reads the poisoned pkcs11.txt configuration and attempts to load the attacker-specified DLL via PR_LoadLibraryWithFlags. The Windows loader executes the DLL’s DllMain entry point immediately upon process attachment, spawning calc.exe as demonstrated in calc_payload.c.

Which files are essential for understanding the exploitation chain?

Key files include README.md (lines 71-84) for the step-by-step chain analysis, build_backup.py for backup generation logic, server.py for payload delivery, and utilmod.c (lines 39-40) for the NSS implementation details regarding module loading.

Is this exploit limited to Firefox 152.0.5 specifically?

The PoC targets Firefox 152.0.5 specifically, but the underlying vulnerability pattern—trusting NSS configuration files delivered through backup restoration—may affect other versions implementing similar backup restore workflows without path validation on PKCS#11 module libraries.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →