Earlier quoted context omitted.
It's possible that the vulnerability only effects Angular running in Firefox addons, and not the general web. Mozilla takes an aggressive stance on what they allow in vetted browser extensions, as they should. JS in addons runs in a different, more privileged environment than normal web pages, and isn't restricted by things like same-origin (although this is improving with Firefox's new extension APIs). Any project t…
In other words, the vulnerability is with Firefox instead of Angular?
It's not safe for a 3 year old to drive a car, even if there's nothing wrong with the baby or the car.