High severity8.8NVD Advisory· Published Feb 28, 2019· Updated Jun 17, 2026
CVE-2018-12391
CVE-2018-12391
Description
During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*range: <63.0
- cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*range: <60.3
- (no CPE)range: <60.3
- (no CPE)range: unspecified
- (no CPE)range: unspecified
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*range: <60.3
- (no CPE)range: <60.3
- (no CPE)range: unspecified
- Range: <63
- osv-coords5 versionspkg:rpm/opensuse/MozillaFirefox&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/MozillaThunderbird&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/firefox-esr&distro=openSUSE%20Tumbleweedpkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015pkg:rpm/suse/MozillaThunderbird&distro=SUSE%20Package%20Hub%2012
< 92.0-1.2+ 4 more
- (no CPE)range: < 92.0-1.2
- (no CPE)range: < 91.1.1-1.1
- (no CPE)range: < 128.5.1-1.1
- (no CPE)range: < 60.3.0-3.17.2
- (no CPE)range: < 60.3.0-74.2
Patches
Vulnerability mechanics
References
8- www.securityfocus.com/bid/105718nvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/105769nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1041944nvdThird Party AdvisoryVDB Entry
- bugzilla.mozilla.org/show_bug.cginvdIssue TrackingPermissions RequiredVendor Advisory
- security.gentoo.org/glsa/201811-13nvdThird Party Advisory
- www.mozilla.org/security/advisories/mfsa2018-26/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2018-27/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2018-28/nvdVendor Advisory
News mentions
0No linked articles in our index yet.