CVE-2022-38473
NixOS vulnerability analysis and mitigation

Overview

CVE-2022-38473 is a high-impact security vulnerability discovered in Mozilla Firefox and Thunderbird browsers that was disclosed on August 23, 2022. The vulnerability affects multiple versions including Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104. The issue allows cross-origin iframes referencing XSLT documents to inherit the parent domain's permissions, such as microphone or camera access (Mozilla Advisory).

Technical details

The vulnerability stems from a flaw in how XSLT document transformations handle feature policies. During XSL transformation, several properties of the source document are transferred to the result document in URIUtils::ResetWithSource(), but the document's FeaturePolicy was not properly considered. As a result, the transformed document retained permissive default settings, which in a nested context (cross-origin iframe) effectively granted blanket delegation of all permissions from the top-level context (Mozilla Bug).

Impact

The vulnerability allows a malicious cross-origin iframe to gain unauthorized access to sensitive permissions that were granted to the parent domain, including microphone and camera access. This could potentially enable attackers to access user media devices without proper authorization, representing a significant privacy and security risk (Mozilla Advisory).

Mitigation and workarounds

Mozilla addressed this vulnerability by releasing security updates across multiple versions. The fix was implemented in Firefox 104, Firefox ESR 102.2, Firefox ESR 91.13, Thunderbird 102.2, and Thunderbird 91.13. Users are advised to update their browsers to these or later versions to mitigate the vulnerability (Mozilla Advisory, Debian Security).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management