#VU71224 Permissions, Privileges, and Access Controls in Mozilla Firefox and Firefox for Android - CVE-2023-23598
Published: January 17, 2023
Mozilla Firefox
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to read arbitrary files on the system.
The vulnerability exists due to improperly imposed security restrictions with the Firefox GTK wrapper. A remote attacker can trick the victim to perform certain actions on the web page, such as drag objects and read arbitrary files on the system via a call to DataTransfer.setData.