CVE-2018-5116 — Origin Validation Error in Mozilla Firefox
Severity
9.8CRITICALNVD
EPSS
0.5%
top 35.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 11
Latest updateMay 14
Description
WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin. Malicious extensions can inject frames from arbitrary origins into the loaded page and then interact with them, bypassing same-origin user expectations with this permission. This vulnerability affects Firefox < 58.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages4 packages
Also affects: Ubuntu Linux 14.04, 16.04, 17.10
🔴Vulnerability Details
4GHSA▶
GHSA-3h65-3mjq-qqj8: WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin↗2022-05-14
OSV▶
CVE-2018-5116: WebExtensions with the "ActiveTab" permission are able to access frames hosted within the active tab even if the frames are cross-origin↗2018-01-23