CVE-2023-25729
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2023-25729 is a vulnerability that affects Firefox versions below 110, Thunderbird below 102.8, and Firefox ESR below 102.8. The issue lies in the way permission prompts are handled for opening external schemes. Instead of being shown for all principals, they are only displayed for ContentPrincipals. This oversight allows extensions to open such schemes using ExpandedPrincipals without requiring user interaction. Malicious actors could exploit this to download files or interact with software already installed on the system, potentially leading to further security risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.