It can, but not for the reason you specified. It would need to run it in the same terminal you run sudo in. Basically, if you got code running as your user, it just has to wait until you run something else with sudo, then it has full access to your machine. I've posted basic bash scripts that would do that in another thread. The key though is that a FF vulnerability would need to be exploited or the code would need some other way to run on your system first.
Bookmarks