CVE-2016-9070: Mozilla Firefox
High severity, CVSS 8.0. EPSS: 1.9% chance of exploitation in the next 30 days.
A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScript operations violating cross-origin protections. This vulnerability affects Firefox < 50.
Affected products
- Mozilla Firefox: before 50 (fixed in 50)
Published 2018-06-11. Last modified 2026-06-17.