First published: Tue Dec 13 2016(Updated: )
Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Firefox < 50.1.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <50.1 | 50.1 |
Firefox | <50.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2016-9896 is classified as a high-severity vulnerability due to the use-after-free issue that can lead to potential code execution.
To fix CVE-2016-9896, update Firefox to version 50.1 or later.
CVE-2016-9896 affects users of Mozilla Firefox versions earlier than 50.1 when WebVR is manipulated.
A use-after-free vulnerability in CVE-2016-9896 occurs when the memory space of an object is accessed after it has been freed, potentially allowing for exploitation.
WebVR is not enabled by default in Firefox, but if it is enabled, CVE-2016-9896 can be exploited.