CVE-2015-7327: Mozilla Firefox
Medium severity, CVSS 4.3. EPSS: 1.8% chance of exploitation in the next 30 days.
Mozilla Firefox before 41.0 does not properly restrict the availability of High Resolution Time API times, which allows remote attackers to track last-level cache access, and consequently obtain sensitive information, via crafted JavaScript code that makes performance.now calls.
Affected products
- Mozilla Firefox: up to and including 40.0.3
Published 2015-09-24. Last modified 2026-06-17.