CVE-2022-29916: Infoleak
Firefox behaved slightly differently for already known resources when loading CSS resources involving CSS variables. This could have been used to probe the browser history.
Other sources
Thunderbird would behave slightly differently for already known resources, when loading CSS resources through resolving CSS variables. This could be used to probe the browser history.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-29916?
The severity of CVE-2022-29916 is classified as moderate.
How do I fix CVE-2022-29916?
To fix CVE-2022-29916, users should update Firefox to version 100 or later for general releases and to Firefox ESR version 91.9 or later.
What software is affected by CVE-2022-29916?
CVE-2022-29916 affects Mozilla Firefox versions up to 100, Mozilla Firefox ESR versions up to 91.9, and Mozilla Thunderbird versions up to 91.9.
Can CVE-2022-29916 lead to data leakage?
Yes, CVE-2022-29916 can be exploited to potentially probe and leak browser history.
Is CVE-2022-29916 a remote attack vector?
CVE-2022-29916 can be exploited via a remote attack if the user visits a malicious website.