CVE-2023-4579: Mozilla Firefox

Low severity, CVSS 3.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Search queries in the default search engine could appear to have been the currently navigated URL if the search query itself was a well formed URL. This could have led to a site spoofing another if it had been maliciously set as the default search engine. This vulnerability affects Firefox < 117.

Affected products

  • Mozilla Firefox: before 117.0 (fixed in 117.0)

Published 2023-09-11. Last modified 2026-06-17.