Related Vulnerabilities: CVE-2018-12369  

WebExtensions bundled with embedded experiments were not correctly checked for proper authorization before Firefox 61.0. This allowed a malicious WebExtension to gain full browser permissions.

Severity Medium

Remote Yes

Type Access restriction bypass

Description

WebExtensions bundled with embedded experiments were not correctly checked for proper authorization before Firefox 61.0. This allowed a malicious WebExtension to gain full browser permissions.

AVG-727 firefox 60.0.2-1 61.0-1 Critical Fixed

27 Jun 2018 ASA-201806-14 AVG-727 firefox Critical multiple issues

https://www.mozilla.org/en-US/security/advisories/mfsa2018-15/#CVE-2018-12369
https://bugzilla.mozilla.org/show_bug.cgi?id=1454909