firefox_focus vulnerabilities
CVEs whose affected-version data names the firefox_focus package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2023-29546Medium· 6.5When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information
When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are…
CVE-2023-29534Critical· 9.1Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android
Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other ve…
CVE-2022-26486Critical· 9.6CISA KEV0dayAn unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.…
CVE-2022-26485High· 8.8CISA KEV0dayPoCRemoving an XSLT parameter during processing could have lead to an exploitable use-after-free
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for A…