Related Vulnerabilities: CVE-2019-11725  

In Firefox before 68.0, when a user navigates to a site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections.

Severity Low

Remote Yes

Type Information disclosure

Description

In Firefox before 68.0, when a user navigates to a site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections.

AVG-1002 firefox 67.0.4-2 68.0-1 Critical Testing

https://www.mozilla.org/en-US/security/advisories/mfsa2019-21/#CVE-2019-11725
https://bugzilla.mozilla.org/show_bug.cgi?id=1483510