CVE-2023-49061

Publication date 21 November 2023

Last updated 1 August 2025


Ubuntu priority

Negligible

Why this priority?

Cvss 3 Severity Score

6.1 · Medium

Score breakdown

An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.

Read the notes from the security team

Status

Package Ubuntu Release Status
firefox 23.10 mantic
Not affected
23.04 lunar
Not affected
22.04 LTS jammy
Not affected
20.04 LTS focal Not in release
18.04 LTS bionic Ignored end of standard support
16.04 LTS xenial Ignored end of standard support
14.04 LTS trusty Ignored end of standard support
thunderbird 23.10 mantic
Not affected
23.04 lunar
Not affected
22.04 LTS jammy
Not affected
20.04 LTS focal Not in release
18.04 LTS bionic Ignored end of standard support
16.04 LTS xenial Ignored end of standard support
14.04 LTS trusty Ignored end of standard support

Notes


tyhicks

mozjs contains a copy of the SpiderMonkey JavaScript engine


mdeslaur

starting with Ubuntu 22.04, the firefox package is just a script that installs the Firefox snap


alexmurray

According to upstream only affects Firefox on iOS so Ubuntu is not affected

Severity score breakdown

Parameter Value
Base score 6.1 · Medium
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Scope Changed
Confidentiality Low
Integrity impact Low
Availability impact None
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N