Firefox Vulnerability: Private Browsing Files Not Properly Deleted

CVE-2024-4767
Currently unrated 🤨

Key Information

Vendor
Mozilla
Status
Firefox
Firefox Esr
Thunderbird
Vendor
CVE Published:
14 May 2024

Summary

If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

Affected Version(s)

Firefox < 126

Firefox ESR < 115.11

Thunderbird < 115.11

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database

Credit

Kim Do Hun via Tor Browser
.