Security restrictions bypass in Mozilla Firefox - CVE-2018-12369
Published: June 27, 2018
Vulnerability identifier: #VU13491
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12369
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The weakness exists due to WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. A remote attacker can use a malicious WebExtension to bypass security restrictions and gain full browser permissions.
The weakness exists due to WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. A remote attacker can use a malicious WebExtension to bypass security restrictions and gain full browser permissions.
Affected software
Mozilla Firefox
Firefox ESR
Arch Linux
Gentoo Linux
openSUSE Leap
Firefox ESR
Arch Linux
Gentoo Linux
openSUSE Leap
How to mitigate CVE-2018-12369
Update to version 61.0.
Mozilla Firefox - update to 61.0