Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.
| Software | From | Fixed in |
|---|---|---|
| mozilla / firefox | - | 116.0 |
| debian / debian_linux | 11.0 | 11.0.x |
| debian / debian_linux | 12.0 | 12.0.x |
| mozilla / firefox | 115.0 | 115.1 |
| mozilla / firefox | 102.0 | 102.14 |