#VU83377 Permissions, Privileges, and Access Controls in Firefox for iOS - CVE-2023-49060
Published: November 21, 2023
Firefox for iOS
Mozilla
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to application does not properly impose security restrictions through <a [referrerpolicy]> in ReaderMode. A local user can access internal pages or data by ex-filtrating a security key from ReaderMode via the referrerpolicy attribute.