CVE-2023-28159: Mozilla Firefox
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 111.
Affected products
- Mozilla Firefox: before 111.0 (fixed in 111.0)
Published 2023-06-02. Last modified 2026-06-17.