Improper access control in Firefox for Android - CVE-2023-6868
Published: December 19, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties.
Affected software
Gentoo Linux
www-client/firefox
How to mitigate CVE-2023-6868
www-client/firefox - update to 104