CVE-2023-3600: Mozilla Firefox
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0.2, and Thunderbird < 115.0.1.
Affected products
- Mozilla Firefox: before 115.0.2 (fixed in 115.0.2)
- Mozilla Firefox ESR: before 115.0.2 (fixed in 115.0.2)
- Mozilla Thunderbird: before 115.0.1 (fixed in 115.0.1)
Published 2023-07-12. Last modified 2026-06-17.