A session hijacker is an attacker who gains unauthorized access to an active web browsing session. Security vulnerabilities in web browsers such as Mozilla Firefox are primarily exploited for this purpose. The attacker uses a manipulated web browser that copies session cookies and other sensitive data. This stolen information is then sent to an attack server, allowing the attacker to take control of the current session. This allows them to steal confidential data or perform actions on behalf of the victim.