CVE-2023-28163: Mozilla Firefox

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resolved those in the context of the current user. <br>*This bug only affects Firefox on Windows. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.

Affected products

  • Mozilla Firefox: before 111.0 (fixed in 111.0)
  • Mozilla Firefox ESR: before 102.9 (fixed in 102.9)
  • Mozilla Thunderbird: before 102.9 (fixed in 102.9)

Published 2023-06-02. Last modified 2026-06-17.