#VU72259 Prototype pollution in Mozilla Firefox - CVE-2023-25731
Published: February 15, 2023
Mozilla Firefox
Mozilla
Description
The vulnerability allows a remote attacker to execute arbitrary JavaScrpit code on the target system.
The vulnerability exists due to URL previews in the network panel of developer tools improperly store URLs. A remote attacker can use query parameters to overwrite global objects in privileged code when rendering URLPreview and perform prototype pollution.