CVE-2019-9808

MEDIUM

Firefox < 66.0 - Origin Validation Error in WebRTC Permission Request

Title source: llm
STIX 2.1

Description

If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 66.

References (2)

Core 2
Core References
Issue Tracking, Permissions Required, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=1434634

Scores

CVSS v3 5.3
EPSS 0.0009
EPSS Percentile 25.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-346
Status published
Products (1)
mozilla/firefox < 66.0
Published Apr 26, 2019
Tracked Since Feb 18, 2026