The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has it open. This vulnerability affects Firefox < 59.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-firefoxUpgrade libxulUpgrade waterfoxUpgrade linux-thunderbirdUpgrade seamonkeyUpgrade firefox-esrUpgrade firefoxUpgrade linux-seamonkeyUpgrade thunderbird | Dec 10, 2025 | Mar 13, 2018 |
| Mfsa2018 06 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox version 59.0 | Jul 12, 2018 | Jun 11, 2018 |
| Suse | — | Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefox-translations-commonUpgrade MozillaFirefox | May 20, 2018 | Mar 14, 2018 |
| Ubuntu | — | Upgrade firefox | Apr 26, 2018 | Mar 14, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub