CVE-2023-29546Medium· 6.5▾ SunlitWhen recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information.
This bug only affects Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.
firefox_focus < 112.0firefox_mobile < 112.0Upgrade past the affected range:
firefox_focus 112.0firefox_mobile 112.0Connected by shared product, vendor, weakness, or advisory.
CVE-2023-29534Critical· 9.1Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android
CVE-2026-74983High· 8.1Mitigation bypass in the Data Loss Prevention component
CVE-2026-74961Critical· 9.1Side-channel in the Web Audio component
CVE-2026-84639Critical· 9.1Uninitialized memory in MIME parsing
CVE-2026-92240Low· 3.4A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird
CVE-2026-92239Medium· 6.1A maliciously constructed IMAP line could cause an out-of-bounds buffer read