CVE-2019-9815

HIGH

Thunderbird <60.7-Firefox <67-Firefox ESR <60.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.5 with an option to disable hyperthreading in applications running untrusted code in a thread through a new sysctl. Firefox now makes use of it on the main thread and any worker threads. *Note: users need to update to macOS 10.14.5 in order to take advantage of this change.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

References (5)

Core 5
Core References
Permissions Required, Third Party Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=1546544
Third Party Advisory x_refsource_misc
https://mdsattacks.com/

Scores

CVSS v3 8.1
EPSS 0.0100
EPSS Percentile 77.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-203
Status published
Products (3)
mozilla/firefox < 67.0
mozilla/firefox_esr < 60.7
mozilla/thunderbird < 60.7
Published Jul 23, 2019
Tracked Since Feb 18, 2026