Your submission was sent successfully! Close

CVE-2018-5179

Published: 26 April 2019

A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to monitor activity by users. Affects all versions prior to Firefox 60.

Priority

Medium

CVSS 3 base score: 7.5

Status

Package Release Status
chromium-browser
Launchpad, Ubuntu, Debian
Upstream
Released (70.0.3538.67)
Ubuntu 18.04 LTS (Bionic Beaver)
Released (70.0.3538.67-0ubuntu0.18.04.1)
Ubuntu 16.04 ESM (Xenial Xerus)
Released (70.0.3538.67-0ubuntu0.16.04.1)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was ignored [no longer updated])
oxide-qt
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 18.04 LTS (Bionic Beaver) Does not exist

Ubuntu 16.04 ESM (Xenial Xerus) Ignored
(Ubuntu touch end-of-life)
Ubuntu 14.04 ESM (Trusty Tahr) Does not exist
(trusty was ignored [Ubuntu touch end-of-life])