← Vulnerability feed

Vulnerability record · CVE-2023-29546 · published 19 June 2023

CVE-2023-29546: Mozilla firefox focus vulnerability

Mozilla · Firefox Focus

When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.

6.5 CVSS 3.1 Medium EPSS 0.49% · top 60.1%
6.5CVSS 3.1 base score
0.49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
19 Aug 2026Last modified by NVD

Description

When recording the screen while in Private Browsing on Firefox for Android the address bar and keyboard were not hidden, potentially leaking sensitive information. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-29546 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2022-26486Firefox WebGPU IPC use-after-free enables sandbox escapeAn unexpected message in the WebGPU IPC framework triggers a use-after-free in Mozilla Firefox, Firefox ESR, Firefox for Android, Thunderbird and Foc…KEVEPSS 2.3%analysed8.8CVE-2022-26485Firefox XSLT parameter removal use-after-freeRemoving an XSLT parameter during processing in Mozilla Firefox could trigger a use-after-free condition. Mozilla reported attacks in the wild abusin…KEVEPSS 14%analysed10.0CVE-2012-1126Freetype memory buffer overflow vulnerabilityFreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (inva…EPSS 5.6%9.8CVE-2026-84135Mozilla firefox mobile improper input validation vulnerabilityOther issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.EPSS 0.45%9.8CVE-2025-55031Mozilla firefox open redirect vulnerabilityMalicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetooth range …EPSS 0.41%9.8CVE-2023-49060Mozilla firefox mobile vulnerabilityAn attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulne…EPSS 0.64%9.3CVE-2012-1128Freetype memory buffer overflow vulnerabilityFreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (NULL…EPSS 4.6%9.3CVE-2012-1129Freetype memory buffer overflow vulnerabilityFreeType before 2.4.9, as used in Mozilla Firefox Mobile before 10.0.4 and other products, allows remote attackers to cause a denial of service (inva…EPSS 3.8%

Source: NIST National Vulnerability Database (record CVE-2023-29546), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.