Security Flaw in Firefox for iOS Exposes Internal Data via Referrer Policy
CVE-2023-49060
9.8CRITICAL
What is CVE-2023-49060?
A flaw has been identified in Firefox for iOS that enables attackers to potentially exfiltrate sensitive internal data by exploiting the referrerpolicy
attribute to gain access to a security key. This vulnerability impacts versions prior to 120 and poses a risk of unauthorized access to internal pages, emphasizing the need for users to update to secure versions to mitigate potential threats.
Affected Version(s)
Firefox for iOS < 120