VYPR
Medium severity4.3NVD Advisory· Published Dec 19, 2023· Updated Jun 17, 2026

CVE-2023-6868

CVE-2023-6868

Description

In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. This could allow empty messages to be sent from unauthorized parties. *This bug only affects Firefox on Android.* This vulnerability affects Firefox < 121.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.