CVE-2019-11716: Mozilla Firefox

High severity, CVSS 8.3. EPSS: 1.4% chance of exploitation in the next 30 days.

Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.

Affected products

  • Mozilla Firefox: before 68.0 (fixed in 68.0)

Published 2019-07-23. Last modified 2026-06-17.