When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prevent the website from re-enabling it without an additional prompt. This was only possible if the website kept recording with the microphone until re-enabling the camera. This vulnerability affects Firefox < 89.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Firefox | Mozilla | 78.11.0 (including) | 89.0 (excluding) | 
| Firefox | Ubuntu | bionic | * | 
| Firefox | Ubuntu | devel | * | 
| Firefox | Ubuntu | focal | * | 
| Firefox | Ubuntu | groovy | * | 
| Firefox | Ubuntu | hirsute | * | 
| Firefox | Ubuntu | impish | * | 
| Firefox | Ubuntu | jammy | * | 
| Firefox | Ubuntu | kinetic | * | 
| Firefox | Ubuntu | lunar | * | 
| Firefox | Ubuntu | mantic | * | 
| Firefox | Ubuntu | noble | * | 
| Firefox | Ubuntu | trusty | * | 
| Firefox | Ubuntu | upstream | * | 
| Firefox | Ubuntu | xenial | * | 
| Mozjs38 | Ubuntu | bionic | * | 
| Mozjs38 | Ubuntu | esm-apps/bionic | * | 
| Mozjs38 | Ubuntu | upstream | * | 
| Mozjs52 | Ubuntu | bionic | * | 
| Mozjs52 | Ubuntu | esm-apps/focal | * | 
| Mozjs52 | Ubuntu | esm-infra/bionic | * | 
| Mozjs52 | Ubuntu | focal | * | 
| Mozjs52 | Ubuntu | groovy | * | 
| Mozjs52 | Ubuntu | upstream | * | 
| Mozjs68 | Ubuntu | esm-infra/focal | * | 
| Mozjs68 | Ubuntu | focal | * | 
| Mozjs68 | Ubuntu | groovy | * | 
| Mozjs68 | Ubuntu | upstream | * | 
| Mozjs78 | Ubuntu | esm-apps/jammy | * | 
| Mozjs78 | Ubuntu | groovy | * | 
| Mozjs78 | Ubuntu | hirsute | * | 
| Mozjs78 | Ubuntu | impish | * | 
| Mozjs78 | Ubuntu | jammy | * | 
| Mozjs78 | Ubuntu | kinetic | * | 
| Mozjs78 | Ubuntu | lunar | * | 
| Mozjs78 | Ubuntu | upstream | * | 
| Thunderbird | Ubuntu | groovy | * | 
| Thunderbird | Ubuntu | trusty | * |