Related Vulnerabilities: CVE-2018-5157  

A same-origin policy bypass vulnerability has been found in the PDF viewer of Firefox < 60.0, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website.

Severity High

Remote Yes

Type Same-origin policy bypass

Description

A same-origin policy bypass vulnerability has been found in the PDF viewer of Firefox < 60.0,  allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website.

AVG-693 firefox 59.0.2-3 60.0-1 Critical Fixed

13 May 2018 ASA-201805-10 AVG-693 firefox Critical multiple issues

https://www.mozilla.org/en-US/security/advisories/mfsa2018-11/#CVE-2018-5157
https://bugzilla.mozilla.org/show_bug.cgi?id=1449898