CVE-2023-29546
CVE-2023-29546 is a medium-severity vulnerability in Mozilla Firefox Focus with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- EPSS exploit prediction: 0% (40th percentile)
- Actively exploited: Not listed in CISA KEV
- Affected product: Mozilla Firefox Focus
- Published:
- Last modified:
Description
When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.
Frequently asked questions
- What is CVE-2023-29546?
- When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.
- How severe is CVE-2023-29546?
- CVE-2023-29546 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2023-29546 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (40th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-29546?
- CVE-2023-29546 primarily affects Mozilla Firefox Focus. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2023-29546?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2023-29546 published?
- CVE-2023-29546 was published on 2023-06-19 and last updated on 2026-08-19.
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1780842
- https://www.mozilla.org/security/advisories/mfsa2023-13/
Affected products (2)
- cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:android:*:*
- cpe:2.3:a:mozilla:firefox_mobile:*:*:*:*:*:android:*:*
More vulnerabilities in Mozilla Firefox Focus
- CVE-2025-55031 — Critical (CVSS 9.8): Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An…
- CVE-2022-26486 — Critical (CVSS 9.6): An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We…
- CVE-2023-29534 — Critical (CVSS 9.1): Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have…
- CVE-2022-26485 — High (CVSS 8.8): Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of…
- CVE-2024-1563 — High (CVSS 8.1): An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an…
- CVE-2026-8945 — High (CVSS 7.5): Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.