CVE-2018-12400 — Sensitive Information Exposure in Mozilla Firefox
Severity
5.3MEDIUMNVD
EPSS
0.3%
top 50.70%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 28
Latest updateMay 14
Description
In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4
Affected Packages3 packages
🔴Vulnerability Details
1GHSA▶
GHSA-wxmw-mw39-8fw9: In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode↗2022-05-14
📋Vendor Advisories
1Debian▶
CVE-2018-12400: firefox - In private browsing mode on Firefox for Android, favicons are cached in the cach...↗2018