cbcvebase.
CVE-2023-23600
published 2023-06-02

CVE-2023-23600: Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to…

PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.49%
39.7th percentile
Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox < 109.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianfirefox
mozillafirefox< 109.0109.0
mozillafirefox
mozillafirefox>= unspecified < 109109

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
vendor_debian6.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.