CVE-2018-18495: Medium severity Mozilla Firefox vulnerability
Last updated 25 August 2025
Other sources
WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-18495?
CVE-2018-18495 is a vulnerability in Mozilla Firefox and Ubuntu Linux that allows WebExtension content scripts to be loaded into about: pages, potentially allowing extensions to interfere with the loading and usage of these pages.
What is the severity of CVE-2018-18495?
CVE-2018-18495 has a severity rating of 6.5 (medium).
How does CVE-2018-18495 affect Mozilla Firefox?
CVE-2018-18495 affects Mozilla Firefox versions up to 64.0.
How does CVE-2018-18495 affect Ubuntu Linux?
CVE-2018-18495 affects Ubuntu Linux versions 14.04, 16.04, 18.04, and 18.10.
How can I fix CVE-2018-18495?
To fix CVE-2018-18495, users should update to Mozilla Firefox version 64.0 or higher.