#VU84570 Improper access control in Firefox for Android - CVE-2023-6868
Published: December 19, 2023
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties.