A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript `location` property to cause a redirection to another site using `performance.getEntries()`. This is a same-origin policy violation and could allow for data theft.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2018-30/#CVE-2018-18494
Statement:
In general, this flaw be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.