Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
The product does not encrypt sensitive or critical information before storage or transmission.
Link | Tags |
---|---|
https://bugzilla.mozilla.org/show_bug.cgi?id=1843046 | issue tracking permissions required |
https://www.mozilla.org/security/advisories/mfsa2023-34/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2023-36/ | vendor advisory |
https://www.mozilla.org/security/advisories/mfsa2023-38/ | vendor advisory |