CVE-2019-9797: Mozilla Firefox
Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.
Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.
Affected products
- Mozilla Firefox: before 66.0 (fixed in 66.0)
Published 2019-04-26. Last modified 2026-06-17.