Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or the geolocation permission.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade seamonkeyUpgrade linux-firefoxUpgrade firefox-esrUpgrade firefoxUpgrade linux-thunderbirdUpgrade libxulUpgrade linux-seamonkeyUpgrade thunderbird | Dec 10, 2025 | Jun 7, 2016 |
| Mfsa2016 57 | — | Upgrade to Mozilla Firefox version 47.0Upgrade to the latest version of Mozilla Firefox | Jun 8, 2016 | Jun 7, 2016 |
| Suse | — | Upgrade MozillaFirefoxUpgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox-devel | Jun 12, 2016 | Jun 11, 2016 |
| Ubuntu | — | Upgrade firefox | Jun 9, 2016 | Jun 9, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub