#VU73680 Permissions, Privileges, and Access Controls in Mozilla Firefox and Firefox for Android - CVE-2023-28161
Published: March 14, 2023
Mozilla Firefox
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to gain access to otherwise restricted functionality.
The vulnerability exists due to way one-time permissions are handled with the browser tab. If temporary "one-time" permissions, such as the ability to use the Camera, were granted to a document loaded using a file: URL, that permission persisted in that tab for all other documents loaded from a file: URL.