CVE-2016-9062: Mozilla Firefox
Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" and "browser.db-wal" files within the Firefox profile after the mode is exited. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.
Affected products
- Mozilla Firefox: before 50.0 (fixed in 50.0)
Published 2018-06-11. Last modified 2026-06-17.