CVE-2023-6869: Mozilla Firefox

Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A `&lt;dialog>` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow untrusted content to display under the guise of trusted content. This vulnerability affects Firefox < 121.

Affected products

  • Mozilla Firefox: before 121.0 (fixed in 121.0)

Published 2023-12-19. Last modified 2026-06-17.