CVE-2023-29547: Mozilla Firefox
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
Affected products
- Mozilla Firefox: before 112.0 (fixed in 112.0)
- Mozilla Firefox ESR: before 102.10 (fixed in 102.10)
- Mozilla Focus: before 112.0 (fixed in 112.0)
Published 2023-06-02. Last modified 2026-06-17.