CVE-2023-49060: Mozilla Firefox Mobile

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability affects Firefox for iOS < 120.

Affected products

  • Mozilla Firefox Mobile: before 120.0 (fixed in 120.0)

Published 2023-11-21. Last modified 2026-08-19.