CVE-2019-9808: Mozilla Firefox

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 66.

Affected products

  • Mozilla Firefox: before 66.0 (fixed in 66.0)

Published 2019-04-26. Last modified 2026-06-17.