CVE-2023-4045

Publication date

2023-08-01 14:56:53

Family

mozilla

State

PUBLISHED

Description

Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.