CVE-2018-18496: Mozilla Firefox
High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.
When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.
Affected products
- Mozilla Firefox: before 64.0 (fixed in 64.0)
Published 2019-02-28. Last modified 2026-06-17.