CVE-2023-25747: Use After Free
A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. This bug only affects Firefox for Android. Other versions of Firefox are unaffected. This vulnerability affects Firefox for Android < 110.1.0.
Other sources
A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30.This bug only affects Firefox for Android. Other versions of Firefox are unaffected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefox for Androidto a version that resolves this vulnerability.Fixed in 110.1.0 - Configuration
Disable the AAudio backend in libaudio when running on Android API below version 30 to address the potential use-after-free.
libaudio (AAudio backend) in Firefox for Android AAudio backend enabled = disabled when Android API level is below 30
Event History
Frequently Asked Questions
What is CVE-2023-25747?
CVE-2023-25747 is a vulnerability in Mozilla Firefox for Android versions below 110.1.0 that allows for a potential use-after-free in libaudio.
Which versions of Mozilla Firefox for Android are affected by CVE-2023-25747?
Mozilla Firefox for Android versions below 110.1.0 are affected by CVE-2023-25747.
How does CVE-2023-25747 affect Firefox for Android?
CVE-2023-25747 affects Firefox for Android by potentially causing a use-after-free vulnerability in the libaudio component.
What is the severity of CVE-2023-25747?
CVE-2023-25747 has a severity level of 7, which is considered high.
How can I fix CVE-2023-25747?
To fix CVE-2023-25747, update your Mozilla Firefox for Android to version 110.1.0 or above.