CVE-2018-18511: Mozilla Firefox

Medium severity, CVSS 4.3. EPSS: 1.9% chance of exploitation in the next 30 days.

Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.

Affected products

Published 2019-04-26. Last modified 2026-06-17.