SB2023071139 - Multiple vulnerabilities in Firefox for iOS



SB2023071139 - Multiple vulnerabilities in Firefox for iOS

Published: July 11, 2023 Updated: March 7, 2025

Security Bulletin ID SB2023071139
Severity
Medium
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Insufficient UI Warning of Dangerous Operations (CVE-ID: CVE-2023-37455)

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to the media permission request prompt from the site in the background tab is overlaid on top of the site in the foreground tab. A remote attacker can perform spoofing attack.


2) Input validation error (CVE-ID: CVE-2023-37456)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper validation in the session restore helper. A remote attacker can pass specially crafted message header with no parameters to the application and perform a denial of service (DoS) attack.


Remediation

Install update from vendor's website.