Directory Path Exposure in Firefox and Focus for Android by Mozilla
CVE-2023-29538

4.3MEDIUM

Key Information:

Vendor
Mozilla
Vendor
CVE Published:
2 June 2023

Summary

A vulnerability in Mozilla's Firefox and Focus for Android allows a WebExtension to receive a jar:file:/// URI instead of the intended moz-extension:/// URI during load requests. This issue can lead to the unintentional exposure of directory paths stored on the user's device, which poses risks related to user privacy and system integrity. The vulnerability is relevant to specific versions of Firefox for Android, Firefox, and Focus for Android prior to version 112.

Affected Version(s)

Firefox < 112

Firefox for Android < 112

Focus for Android < 112

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.