First published: Tue Oct 23 2018(Updated: )
During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <60.3 | 60.3 |
<63 | 63 | |
<60.3 | 60.3 | |
<60.3 | 60.3 | |
Mozilla Firefox | <63.0 | |
Mozilla Firefox ESR | <60.3 | |
Mozilla Thunderbird | <60.3 | |
Google Android |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-12391 is a vulnerability that allows audio data to be accessed across origins in violation of security policies during HTTP Live Stream playback on Firefox for Android.
The severity of CVE-2018-12391 is critical with a CVSS score of 8.8.
Mozilla Firefox versions up to and excluding 63.0, Mozilla Firefox ESR versions up to and excluding 60.3, and Mozilla Thunderbird versions up to and excluding 60.3 are affected by CVE-2018-12391.
To fix CVE-2018-12391, update your Mozilla Firefox or Mozilla Thunderbird to the latest version available.
You can find more information about CVE-2018-12391 on the Mozilla security advisories: mfsa2018-27 and mfsa2018-28.