First published: Tue Dec 11 2018(Updated: )
When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <64 | 64 |
<64 | 64 | |
Mozilla Firefox | <64.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-18496 is a vulnerability in Mozilla Firefox that allows for a clickjacking attack by confusing users into downloading and executing an executable file.
CVE-2018-18496 only affects Windows operating systems.
CVE-2018-18496 has a severity rating of 8.8 (high).
Update your Mozilla Firefox browser to version 64 or higher.
You can find more information about CVE-2018-18496 on the Mozilla Bugzilla and Mozilla Security Advisories websites.