#VU17654 Permissions, Privileges, and Access Controls in Mozilla Firefox - CVE-2018-18511
Published: February 13, 2019
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to bypass same-origin policy.
The vulnerability exists due to an error when processing canvas elements with transferFromImageBitmap method. A remote attacker can create a specially crafted website, trick the victim into visiting it, bypass cross-origin policy and view images loaded in other browser tabs.