CVE-2023-29546
published 2023-06-19CVE-2023-29546: When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive…
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.49%
39.0th percentile
When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information.
*This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | — | — |
| mozilla | firefox | < 112.0 | 112.0 |
| mozilla | firefox | — | — |
| mozilla | firefox_focus | < 112.0 | 112.0 |
| mozilla | firefox_for_android | >= unspecified < 112 | 112 |
| mozilla | focus_for_android | >= unspecified < 112 | 112 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_oracle7.5HIGH
vendor_debian6.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (NekoHTML) — CVE-2022-29546
vendor_oracle·2023-10-15·CVSS 7.5
CVE-2022-29546 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (NekoHTML) — CVE-2022-29546
Oracle Oracle Fusion Middleware Risk Matrix: Centralized Thirdparty Jars (NekoHTML) vulnerability
CVE: CVE-2022-29546
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (NekoHTML) — CVE-2022-29546
vendor_oracle·2023-07-15·CVSS 7.5
CVE-2022-29546 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (NekoHTML) — CVE-2022-29546
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (NekoHTML) vulnerability
CVE: CVE-2022-29546
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Debian
CVE-2023-29546: firefox - When recording the screen while in Private Browsing on Firefox for Android the a...
vendor_debian·2023·CVSS 6.5
CVE-2023-29546 [MEDIUM] CVE-2023-29546: firefox - When recording the screen while in Private Browsing on Firefox for Android the a...
When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.
Scope: local
sid: resolved
Mozilla
Mozilla Foundation Security Advisory 2023-13: CVE-2023-29546
vendor_mozilla·CVSS 6.5
CVE-2023-29546 [MEDIUM] Mozilla Foundation Security Advisory 2023-13: CVE-2023-29546
Mozilla Foundation Security Advisory 2023-13
CVE: CVE-2023-29546
Product: Firefox, Firefox for Android, Focus for Android
Impact: high
Fixed in: Firefox 112
Firefox for Android 112
Focus for Android 112
GHSA
GHSA-rh4w-355m-vr23: When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive
ghsa_unreviewed·2023-06-19
CVE-2023-29546 [MEDIUM] GHSA-rh4w-355m-vr23: When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive
When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information.
*This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.
OSV
CVE-2023-29546: When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive
osv·2023-06-19·CVSS 6.5
CVE-2023-29546 [MEDIUM] CVE-2023-29546: When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive
When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-06-19
Published