CVE-2022-46875: Mozilla Firefox
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
Affected products
- Mozilla Firefox: before 108.0 (fixed in 108.0)
- Mozilla Firefox ESR: before 102.6 (fixed in 102.6)
- Mozilla Thunderbird: before 102.6 (fixed in 102.6)
Published 2022-12-22. Last modified 2026-06-17.