CVE-2018-5179: Mozilla Firefox

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to monitor activity by users. Affects all versions prior to Firefox 60.

Affected products

  • Mozilla Firefox: before 60.0 (fixed in 60.0)

Published 2019-04-26. Last modified 2026-06-17.