CVE-2023-23600

Advisory lineage Upstream: 0 Downstream: 2
Modified
Published: 02 Jun 2023, 00:00
Last modified:18 Dec 2025, 15:23

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.28% LOW
0% probability +0.09%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

02 Jun 2023, 00:00
Published
Vulnerability first disclosed
18 Dec 2025, 15:23
Last Modified
Vulnerability information updated

Description

Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox < 109.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.28% Percentile: 51%

Affected Systems

  • mozillafirefox

    < 109.0 | ≥ unspecified, < 109

References (2)