Security researcher André Bargull reported that when a web page creates a scripted proxy for the window with a handler defined a certain way, a reference to the inner window will be passed, rather than that of the outer window in violation of the specification. External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2015-108/
Acknowledgements: Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges André Bargull as the original reporter.
This issue was fixed in Firefox version 41.