Candidate: CVE-2018-5179 PublicDate: 2019-04-26 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5179 Description: A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to monitor activity by users. Affects all versions prior to Firefox 60. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [7.5 HIGH] Patches_chromium-browser: upstream_chromium-browser: released (70.0.3538.67) precise/esm_chromium-browser: DNE trusty_chromium-browser: ignored (no longer updated) trusty/esm_chromium-browser: DNE (trusty was ignored [no longer updated]) xenial_chromium-browser: released (70.0.3538.67-0ubuntu0.16.04.1) bionic_chromium-browser: released (70.0.3538.67-0ubuntu0.18.04.1) cosmic_chromium-browser: released (70.0.3538.67-0ubuntu0.18.10.1) devel_chromium-browser: released (70.0.3538.67-0ubuntu0.18.10.1) Patches_oxide-qt: upstream_oxide-qt: needs-triage precise/esm_oxide-qt: DNE trusty_oxide-qt: ignored (Ubuntu touch end-of-life) trusty/esm_oxide-qt: DNE (trusty was ignored [Ubuntu touch end-of-life]) xenial_oxide-qt: ignored (Ubuntu touch end-of-life) esm-infra/xenial_oxide-qt: ignored (Ubuntu touch end-of-life) bionic_oxide-qt: DNE cosmic_oxide-qt: DNE devel_oxide-qt: DNE