A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user with local access puts chrome.manifest and other referenced files in this directory, they will be loaded and activated during startup. This could result in malicious software being added without consent or modification of referenced installed files. This vulnerability affects Firefox < 52.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 11, 2018 |
| Freebsd | — | Upgrade firefoxUpgrade linux-seamonkeyUpgrade linux-firefoxUpgrade firefox-esrUpgrade seamonkeyUpgrade thunderbirdUpgrade libxulUpgrade linux-thunderbird | Mar 8, 2017 | Mar 7, 2017 |
| Mfsa2017 05 | — | Upgrade to Mozilla Firefox version 52.0Upgrade to the latest version of Mozilla Firefox | Mar 8, 2017 | Mar 7, 2017 |
| Suse | — | Upgrade MozillaFirefox-develUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translations-common | Mar 15, 2017 | Mar 7, 2017 |
| Ubuntu | — | Upgrade firefox | Mar 8, 2017 | Mar 7, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub