AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-29909

HIGH · CVSS 8.8 EPSS 0.85%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-12-22 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It affects Firefox.

CVE
CVE-2022-29909
Severity
HIGH
CVSS
8.8
EPSS
0.85%
Firefox

Original NVD Description

Documents in deeply-nested cross-origin browsing contexts could have obtained permissions granted to the top-level origin, bypassing the existing prompt and wrongfully inheriting the top-level permissions. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.

Related CVEs

Other vulnerabilities affecting the same vendor(s)