CVE-2023-23600: Notification permissions persisted between Normal and Private Browsing on Android
Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions. This bug only affects Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 109.
Other sources
Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions.<br>This bug only affects Firefox for Android. Other operating systems are unaffected.. This vulnerability affects Firefox < 109.
Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions.This bug only affects Firefox for Android. Other operating systems are unaffected.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-23600.
What is the severity of CVE-2023-23600?
The severity of CVE-2023-23600 is medium, with a severity value of 6.5.
Which software is affected by CVE-2023-23600?
CVE-2023-23600 affects Mozilla Firefox for Android.
How can I fix CVE-2023-23600?
To fix CVE-2023-23600, update your Mozilla Firefox for Android to version 109.0 or later.
Where can I find more information about CVE-2023-23600?
More information about CVE-2023-23600 can be found in the Mozilla Security Advisory MFS2023-01 and the Bugzilla entry.