Permissions, Privileges, and Access Controls in Mozilla Firefox - CVE-2019-9817
Published: May 21, 2019
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to incorrect access restrictions when reading images from a different domain. A remote attacker can use a canvas object under certain circumstances to violate same-origin policy and read image data from another domain name.