First published: Tue Nov 26 2024(Updated: )
On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <133 | 133 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2024-11703 is classified as a moderate severity vulnerability affecting Firefox versions prior to 133.
To fix CVE-2024-11703, update your Firefox browser to version 133 or later.
Users of Firefox versions prior to 133 on Android are affected by CVE-2024-11703.
CVE-2024-11703 allows viewing saved passwords without requiring the device PIN authentication on affected versions of Firefox.
CVE-2024-11703 was disclosed publicly as part of a Mozilla security advisory.