If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 66.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2019-19170 | If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 66. |
![]() |
USN-3918-1 | Firefox vulnerabilities |
![]() |
USN-3918-2 | Firefox vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: mozilla
Published:
Updated: 2024-08-04T22:01:54.667Z
Reserved: 2019-03-14T00:00:00
Link: CVE-2019-9808

No data.

Status : Modified
Published: 2019-04-26T17:29:03.807
Modified: 2024-11-21T04:52:21.090
Link: CVE-2019-9808

No data.

No data.