Loading HuntDB...

GHSA-7mvx-m8hq-f37g

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage. This vulnerability affects Firefox < 98.

Related CVEs

Key Information

GHSA ID
GHSA-7mvx-m8hq-f37g
Published
December 22, 2022 9:30 PM
Last Modified
April 16, 2025 3:34 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 15, 2025 6:32 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.