Bugzilla – Bug 1149290
VUL-0: CVE-2019-11749: MozillaFirefox: Camera information available without prompting using getUserMedia
Last modified: 2020-02-04 14:46:14 UTC
CVE-2019-11749: Camera information available without prompting using getUserMedia Reporter Andreas Pehrson Impact moderate Description A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification. This allows for the potential fingerprinting of users. References: https://www.mozilla.org/en-US/security/advisories/mfsa2019-26/#CVE-2019-11749 https://bugzilla.mozilla.org/show_bug.cgi?id=1565374 https://bugzilla.redhat.com/show_bug.cgi?id=1748666 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-11749
Closing