If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown protocol" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 59.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade seamonkeyUpgrade linux-firefoxUpgrade firefoxUpgrade waterfoxUpgrade thunderbirdUpgrade libxulUpgrade linux-seamonkeyUpgrade firefox-esrUpgrade linux-thunderbird | Dec 10, 2025 | Mar 13, 2018 |
| Mfsa2018 06 | — | Upgrade to Mozilla Firefox version 59.0Upgrade to the latest version of Mozilla Firefox | Jul 12, 2018 | Jun 11, 2018 |
| Suse | — | Upgrade MozillaFirefox-translations-commonUpgrade MozillaFirefoxUpgrade MozillaFirefox-translations-other | May 20, 2018 | Mar 14, 2018 |
| Ubuntu | — | Upgrade firefox | Apr 26, 2018 | Mar 14, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub