Cross-origin policy bypass in Mozilla Firefox - CVE-2018-12391
Published: October 24, 2018
Vulnerability identifier: #VU15489
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12391
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The weakness exists due to audio data can be accessed across origins in violation of security policies during HTTP Live Stream playback on Firefox for Android. A remote attacker can trick the victim into visiting a specially crafted website, bypass cross-origin policies and conduct further attacks.
The weakness exists due to audio data can be accessed across origins in violation of security policies during HTTP Live Stream playback on Firefox for Android. A remote attacker can trick the victim into visiting a specially crafted website, bypass cross-origin policies and conduct further attacks.
Affected software
Mozilla Firefox
Firefox ESR
Gentoo Linux
Opensuse
Mozilla Thunderbird
Firefox ESR
Gentoo Linux
Opensuse
Mozilla Thunderbird
How to mitigate CVE-2018-12391
Update to version 63.0.
Mozilla Firefox - update to 63.0
Mozilla Thunderbird - update to 60.3
Firefox ESR - update to 60.3.0
Mozilla Thunderbird - update to 60.3
Firefox ESR - update to 60.3.0