We extract all of the natives we need to operate Snow from within an iframe that is immediately detached from DOM to prevent attackers from accessing the natives' realm and abusing it.
Apparently in Firefox, if a call to addEventListener is made and that addEventListener originated in a detached realm, Firefox ignores it (even if the function is called on an object of another realm that is correctly attached and live).
Possible solution:
Instead of detaching the assisting iframe, hide it in a ShadowDOM.
make a unique non-changeable copy of specifically addEventListener from the top main realm instead of the detached iframe.
We extract all of the natives we need to operate Snow from within an iframe that is immediately detached from DOM to prevent attackers from accessing the natives' realm and abusing it.
Apparently in Firefox, if a call to
addEventListener
is made and thataddEventListener
originated in a detached realm, Firefox ignores it (even if the function is called on an object of another realm that is correctly attached and live).Possible solution:
addEventListener
from the top main realm instead of the detached iframe.