Mozilla · Firefox For Android · CVE-2023-29538
**Name of the Vulnerable Software and Affected Versions**
Firefox versions prior to 112
Firefox for Android versions prior to 112
Focus for Android versions prior to 112
**Description**
A vulnerability in the WebExtension component of the Firefox browser is related to the disclosure of information in an error data area. Under specific circumstances, a WebExtension may have received a `jar:file:///` URI instead of a `moz-extension:///` URI during a load request, leaking directory paths on the user's machine.
**Recommendations**
For Firefox versions prior to 112, update to version 112 or later.
For Firefox for Android versions prior to 112, update to version 112 or later.
For Focus for Android versions prior to 112, update to version 112 or later.