CVE detail
CVE-2023-6868 — CVE-2023-6868
Published 2023-12-19 · Modified 2026-06-17 · Vendor mozilla · Product firefox · Source nvd
MEDIUM
severity
CVSS-derived band
0.0049
EPSS probability
exploitation probability, 30d
40.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties.
*This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References