During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. Note: this issue only occurs on Windows. Other operating systems are unaffected.. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 72.0 |
| mozilla / firefox_esr | - | 68.4 |
| opensuse / leap | 15.1 | 15.1.x |