SB2023071139 - Multiple vulnerabilities in Firefox for iOS
Published: July 11, 2023 Updated: March 7, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Insufficient UI Warning of Dangerous Operations (CVE-ID: CVE-2023-37455)
The vulnerability allows a remote attacker to perform spoofing attack.
The vulnerability exists due to the media permission request prompt from the site in the background tab is overlaid on top of the site in the foreground tab. A remote attacker can perform spoofing attack.
2) Input validation error (CVE-ID: CVE-2023-37456)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper validation in the session restore helper. A remote attacker can pass specially crafted message header with no parameters to the application and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.