4.3
CVSSv3

CVE-2022-26382

Published: 22/12/2022 Updated: 30/12/2022
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage. This vulnerability affects Firefox < 98.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla firefox

Vendor Advisories

Firefox could be made to crash or run programs as your login if it opened a malicious website ...
USN-5321-1 introduced minor regressions in Firefox ...
Firefox could be made to crash or run programs as your login if it opened a malicious website ...
Mozilla Foundation Security Advisory 2022-10 Security Vulnerabilities fixed in Firefox 98 Announced March 8, 2022 Impact high Products Firefox Fixed in Firefox 98 ...
While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage ...