Activity-stream is only enabled in Nightly, and if activity-stream is not enabled, about:newtab is loaded without the flag nsIAboutModule::URI_SAFE_FOR_UNTRUSTED_CONTENT, so it will be loaded with System Principal.
Activity-stream is only enabled in Nightly, and if activity-stream is not enabled, about:newtab is loaded without the flag nsIAboutModule::URI_SAFE_FOR_UNTRUSTED_CONTENT, so it will be loaded with System Principal.