Vulnerability Description
When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content. This vulnerability affects Firefox for iOS < 129.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | - |
Related Weaknesses (CWE)
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=1837916ExploitIssue Tracking
- https://www.mozilla.org/security/advisories/mfsa2024-36/
- https://bugzilla.mozilla.org/show_bug.cgi?id=1837916ExploitIssue Tracking
FAQ
What is CVE-2024-0953?
CVE-2024-0953 is a vulnerability with a CVSS score of 6.1 (MEDIUM). When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them...
How severe is CVE-2024-0953?
CVE-2024-0953 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-0953?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox.