#VU18036 Permissions, Privileges, and Access Controls in Mozilla Firefox - CVE-2019-9797
Published: March 21, 2019
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to gain unauthorized access to sensitive information.
The vulnerability exists due to incorrect implementation of the cross-origin policy when reading images using createImageBitmap. A remote attacker can trick the victim into visiting a specially crafted web page and gain access to images opened in other browser tabs.