Memory safety bugs present in Firefox 111. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | gentoo-linux-upgrade-www-client-firefoxgentoo-linux-upgrade-www-client-firefox-bin | May 31, 2023 | May 30, 2023 | |
| Mfsa2023 13 | mozilla-firefox-upgrade-112_0 | Apr 12, 2023 | Apr 11, 2023 | |
| Ubuntu | ubuntu-upgrade-firefox | Apr 17, 2023 | Apr 12, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub