CVE-2018-5132: Infoleak
Last updated 25 August 2025
Other sources
The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has it open. This vulnerability affects Firefox < 59.
— Launchpad
The Find API for WebExtensions can search some privileged pages, such as about:debugging, if these pages are open in a tab. This could allow a malicious WebExtension to search for otherwise protected data if a user has it open.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2018-5132?
CVE-2018-5132 is a vulnerability that affects Firefox versions prior to 59.
How does CVE-2018-5132 work?
CVE-2018-5132 allows a malicious WebExtension to search privileged pages, such as 'about:debugging', if they are open in a tab.
What is the severity of CVE-2018-5132?
The severity of CVE-2018-5132 is medium with a CVSS score of 6.5.
Which software is affected by CVE-2018-5132?
This vulnerability affects Firefox versions prior to 59.
How can I fix CVE-2018-5132?
To fix CVE-2018-5132, update your Firefox to version 59 or later.