CVE-2023-4583: Browsing Context potentially not cleared when closing Private Window
Last updated 24 July 2024
Other sources
When checking if the Browsing Context had been discarded in HttpBaseChannel, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-36/#CVE-2023-4583
— Red Hat
When checking if the Browsing Context had been discarded in HttpBaseChannel, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
— Launchpad
When checking if the Browsing Context had been discarded in HttpBaseChannel, if the load group was not available then it was assumed to have already been discarded which was not always the case for private channels after the private session had ended.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-4583?
The severity of CVE-2023-4583 is high with a CVSS score of 7.5.
Which software versions are affected by CVE-2023-4583?
CVE-2023-4583 affects Firefox versions before 117 and Thunderbird versions before 115.2.
How does CVE-2023-4583 impact private channels?
When the load group is not available, CVE-2023-4583 incorrectly assumes that the Browsing Context has been discarded, potentially leading to security issues for private channels after the private session ends.
Is there a fix for CVE-2023-4583?
Yes, upgrading to Firefox version 117 or Thunderbird version 115.2 will fix the vulnerability.
Where can I find more information about CVE-2023-4583?
You can find more information about CVE-2023-4583 on the MITRE CVE website, Ubuntu security notices, and the NVD website.