Service Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers being written to disk for websites visited in Private Browsing Mode. This would not have persisted them in a state where they would run again, but it would have leaked Private Browsing Mode details to disk. This vulnerability affects Firefox < 107.
References
Link | Resource |
---|---|
https://www.mozilla.org/security/advisories/mfsa2022-47/ | Vendor Advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=1794508 | Issue Tracking Permissions Required Vendor Advisory |
Configurations
Information
Published : 2022-12-22 12:15
Updated : 2023-01-04 11:42
NVD link : CVE-2022-45417
Mitre link : CVE-2022-45417
JSON object : View
CWE
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
Products Affected
mozilla
- firefox