← Back to CVE List

CVE-2023-6868

Published: 2023-12-19T14:15Z
Last Modified: 2024-11-21T08:44Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt