First published: Tue Aug 23 2022(Updated: )
A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.<br />*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 104.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <104 | 104 |
<104 | 104 | |
Mozilla Firefox | <104.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2022-38474 is classified as a moderate severity vulnerability due to its potential to capture audio without user notification.
To remediate CVE-2022-38474, update your Mozilla Firefox to version 104 or later.
CVE-2022-38474 affects users of Mozilla Firefox versions earlier than 104 on desktop and mobile platforms.
CVE-2022-38474 may lead to unauthorized audio recordings being made without the user's knowledge, compromising user privacy.
No, CVE-2022-38474 does not bypass microphone permissions, but it affects the notification system after permission has been granted.