CVE-2023-29534Critical· 9.1▾ MidnightDifferent techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other ve…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
0.7% → 0.7%
Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks.
This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.
firefox_focus < 112.0firefox_mobile < 112.0Upgrade past the affected range:
firefox_focus 112.0firefox_mobile 112.0Connected by shared product, vendor, weakness, or advisory.
CVE-2023-29546Medium· 6.5When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information
CVE-2026-74983High· 8.1Mitigation bypass in the Data Loss Prevention component
CVE-2026-74961Critical· 9.1Side-channel in the Web Audio component
CVE-2026-84639Critical· 9.1Uninitialized memory in MIME parsing
CVE-2026-92240Low· 3.4A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird
CVE-2026-92239Medium· 6.1A maliciously constructed IMAP line could cause an out-of-bounds buffer read