AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-9815

HIGH · CVSS 8.1 EPSS 1.83%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-07-23 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-9815
Severity
HIGH
CVSS
8.1
EPSS
1.83%
Firefox

Original NVD Description

If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.5 with an option to disable hyperthreading in applications running untrusted code in a thread through a new sysctl. Firefox now makes use of it on the main thread and any worker threads. *Note: users need to update to macOS 10.14.5 in order to take advantage of this change.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.