CVE-2022-38474: Medium severity Mozilla Firefox vulnerability
A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.<br />This bug only affects Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 104.
Other sources
A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.This bug only affects Firefox for Android. Other operating systems are unaffected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 104
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2022-38474?
CVE-2022-38474 is classified as a moderate severity vulnerability due to its potential to capture audio without user notification.
How do I fix CVE-2022-38474?
To remediate CVE-2022-38474, update your Mozilla Firefox to version 104 or later.
Who is affected by CVE-2022-38474?
CVE-2022-38474 affects users of Mozilla Firefox versions earlier than 104 on desktop and mobile platforms.
What is the impact of CVE-2022-38474 on user privacy?
CVE-2022-38474 may lead to unauthorized audio recordings being made without the user's knowledge, compromising user privacy.
Is CVE-2022-38474 a direct bypass of microphone permissions?
No, CVE-2022-38474 does not bypass microphone permissions, but it affects the notification system after permission has been granted.