CVE-2018-18495: Canonical Ubuntu Linux

Medium severity, CVSS 6.5. EPSS: 1.9% chance of exploitation in the next 30 days.

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Mozilla Firefox: before 64.0 (fixed in 64.0)

Published 2019-02-28. Last modified 2026-06-17.