First published: Tue Jan 07 2025(Updated: )
The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <134 | |
Firefox ESR | <128.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2336182 is critical due to the potential for privilege escalation attacks.
To fix REDHAT-BUG-2336182, upgrade your Firefox to version 134 or Firefox ESR to version 128.6 or later.
Firefox versions earlier than 134 and Firefox ESR versions earlier than 128.6 are affected by REDHAT-BUG-2336182.
Yes, REDHAT-BUG-2336182 may lead to data breaches due to privilege escalation vulnerabilities.
There are no official workarounds for REDHAT-BUG-2336182; the recommended action is to apply the necessary updates.