CVE-2018-5116: Critical severity firefox vulnerability
Last updated 24 July 2024
Other sources
WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58.
— Launchpad
WebExtensions with the ActiveTab permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5091
- CVE-2018-5092
- CVE-2018-5093
- CVE-2018-5094
- CVE-2018-5095
- CVE-2018-5097
- CVE-2018-5098
- CVE-2018-5099
- CVE-2018-5100
- CVE-2018-5101
- CVE-2018-5102
- CVE-2018-5103
- CVE-2018-5104
- CVE-2018-5105
- CVE-2018-5106
- CVE-2018-5107
- CVE-2018-5108
- CVE-2018-5109
- CVE-2018-5110
- CVE-2018-5111
- CVE-2018-5112
- CVE-2018-5113
- CVE-2018-5114
- CVE-2018-5115
- CVE-2018-5116
- CVE-2018-5117
- CVE-2018-5118
- CVE-2018-5119
- CVE-2018-5121
- CVE-2018-5122
- CVE-2018-5090
- CVE-2018-5089
Frequently Asked Questions
What is CVE-2018-5116?
CVE-2018-5116 is a vulnerability where WebExtensions with the ActiveTab permission can access frames hosted within the active tab, even if the frames are cross-origin.
How does CVE-2018-5116 affect Mozilla Firefox?
CVE-2018-5116 affects Mozilla Firefox versions up to and including 58.0.4.
How can malicious extensions exploit CVE-2018-5116?
Malicious extensions can inject frames from arbitrary origins into the loaded page and interact with them, bypassing same-origin user expectations.
What is the severity of CVE-2018-5116?
CVE-2018-5116 has a severity rating of 9.8, which is considered critical.
Where can I find more information about CVE-2018-5116?
You can find more information about CVE-2018-5116 on the Mozilla Bugzilla and Mozilla Security Advisories websites.