#VU74837 Spoofing attack in Mozilla products - CVE-2023-29547
Published: April 11, 2023
Mozilla Firefox
Firefox for Android
Firefox Focus for Android
Mozilla
Description
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to insecure handling of cookies in Firefox cookie jar. When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie.