Incorrect icon displayed on permissions notifications

Related Vulnerabilities: CVE-2016-2829  

Mozilla Foundation Security Advisory 2016-57

Incorrect icon displayed on permissions notifications

Announced
June 7, 2016
Reporter
Tim McCormack
Impact
Low
Products
Firefox
Fixed in
  • Firefox 47

Description

Security researcher Tim McCormack reported that when a page requests a series of permissions in a short timespan, the resulting permission notifications can show the icon for the wrong permission request. This can lead to user confusion and inadvertent consent given when a user is prompted by web content to give permissions, such as for geolocation or microphone access.

References