Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 28, 2019 |
| Freebsd | — | Upgrade libxulUpgrade waterfoxUpgrade seamonkeyUpgrade linux-firefoxUpgrade linux-seamonkeyUpgrade firefoxUpgrade thunderbirdUpgrade firefox-esrUpgrade linux-thunderbird | Dec 12, 2018 | Dec 11, 2018 |
| Mfsa2018 29 | — | Upgrade to Mozilla Firefox version 64.0 | Dec 12, 2018 | Dec 11, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Feb 28, 2019 |
| Ubuntu | — | Upgrade firefox | Jan 10, 2019 | Dec 11, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub