An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox < 58.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-seamonkeyUpgrade linux-thunderbirdUpgrade firefoxUpgrade thunderbirdUpgrade firefox-esrUpgrade seamonkeyUpgrade waterfoxUpgrade linux-firefoxUpgrade libxul | Dec 10, 2025 | Jan 23, 2018 |
| Mfsa2018 02 | — | Upgrade to Mozilla Firefox version 58.0 | Jan 24, 2018 | Jan 23, 2018 |
| Suse | — | Upgrade mozillafirefox-translations-commonUpgrade mozillafirefoxUpgrade mozillafirefox-translations-other | May 20, 2018 | Jan 24, 2018 |
| Ubuntu | — | Upgrade firefox | Apr 26, 2018 | Jan 24, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub