CVE-2018-18496: Mozilla Firefox

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.

Affected products

  • Mozilla Firefox: before 64.0 (fixed in 64.0)

Published 2019-02-28. Last modified 2026-06-17.