CVE-2023-4580: Mozilla Firefox
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
Affected products
- Mozilla Firefox: before 117.0 (fixed in 117.0)
- Mozilla Firefox ESR: before 115.2 (fixed in 115.2)
- Mozilla Thunderbird: before 115.2 (fixed in 115.2)
Published 2023-09-11. Last modified 2026-06-17.