CVE-2017-7844: Infoleak
A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which pages a user has in their history. This can allow a malicious website to query user history. Note: This issue only affects Firefox 57. Earlier releases are not affected.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-7844?
CVE-2017-7844 is a vulnerability in Mozilla Firefox that allows a malicious website to query user history.
Which versions of Mozilla Firefox are affected by CVE-2017-7844?
Mozilla Firefox versions up to and including 57.0.1 are affected by CVE-2017-7844.
How can a malicious website exploit CVE-2017-7844?
By using a combination of an external SVG image and the coloring of anchor links stored within the image, a malicious website can determine the user's browsing history.
What is the severity level of CVE-2017-7844?
CVE-2017-7844 has a severity level of 6.5 (high).
How to fix the CVE-2017-7844 vulnerability?
Upgrade to Mozilla Firefox version 57.0.1 or later to fix the CVE-2017-7844 vulnerability.