CVE-2023-3482: Mozilla Firefox

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using an iframe with a source of 'about:blank'. This could have led to malicious websites storing tracking data without permission. This vulnerability affects Firefox < 115.

Affected products

  • Mozilla Firefox: before 115.0 (fixed in 115.0)

Published 2023-07-05. Last modified 2026-06-17.